2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-31200CRITICAL9.8A memory corruption issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4.1 and iPadOS 18.4...
CVE-2025-2291CRITICAL9.8Password can be used past expiry in PgBouncer due to auth_query not taking into account Postgres its VALID UNTIL value, ...
CVE-2025-27540CRITICAL9.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-27539CRITICAL9.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-27495CRITICAL9.8A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is v...
CVE-2025-3694CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Web-based Pharmacy Product Management System 1.0...
CVE-2025-22088CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: RDMA/erdma: Prevent use-after-free in erdma_accept_...
CVE-2025-3693CRITICAL9.8A vulnerability was found in Tenda W12 3.0.0.5. It has been rated as critical. Affected by this issue is the function cg...
CVE-2025-3690CRITICAL9.8A vulnerability was found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This issue affects s...
CVE-2025-3689CRITICAL9.8A vulnerability has been found in PHPGurukul Men Salon Management System 1.0 and classified as critical. This vulnerabil...
CVE-2025-39601CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in WPFactory Custom CSS, JS & PHP custom-css allows Remote Code Inclusio...
CVE-2025-39557CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-wo...
CVE-2025-1981CRITICAL9.4Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices...
CVE-2025-1980CRITICAL9.4The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If ...
CVE-2025-3684CRITICAL9.8A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. Th...
CVE-2025-3683CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow...
CVE-2025-3682CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of...
CVE-2025-3681CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f...
CVE-2025-3680CRITICAL9.8A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a...
CVE-2025-3679CRITICAL9.8A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function ...
CVE-2025-3678CRITICAL9.8A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk...
CVE-2025-3676CRITICAL9.8A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the f...
CVE-2025-3495CRITICAL9.8Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker ...
CVE-2025-30215CRITICAL9.6NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f...
CVE-2025-30967CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now