2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-39557CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-wo...
CVE-2025-1981CRITICAL9.4Improper neutralization of input provided by a low-privileged user into a file search functionality in Ready_'s Invoices...
CVE-2025-1980CRITICAL9.4The Ready_ application's Profile section allows users to upload files of any type and extension without restriction. If ...
CVE-2025-3684CRITICAL9.8A vulnerability was found in Xianqi Kindergarten Management System 2.0 Bulid 20190808. It has been rated as critical. Th...
CVE-2025-3683CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been declared as critical. This vulnerability affects unknow...
CVE-2025-3682CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been classified as critical. This affects an unknown part of...
CVE-2025-3681CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this issue is some unknown f...
CVE-2025-3680CRITICAL9.8A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. Affected by this vulnerability is a...
CVE-2025-3679CRITICAL9.8A vulnerability, which was classified as critical, was found in PCMan FTP Server 2.0.7. Affected is an unknown function ...
CVE-2025-3678CRITICAL9.8A vulnerability, which was classified as critical, has been found in PCMan FTP Server 2.0.7. This issue affects some unk...
CVE-2025-3676CRITICAL9.8A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the f...
CVE-2025-3495CRITICAL9.8Delta Electronics COMMGR v1 and v2 uses insufficiently randomized values to generate session IDs (CWE-338). An attacker ...
CVE-2025-30215CRITICAL9.6NATS-Server is a High-Performance server for NATS.io, the cloud and edge native messaging system. In versions starting f...
CVE-2025-30967CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This i...
CVE-2025-30510CRITICAL9.8An attacker can upload an arbitrary file instead of a plant image.
CVE-2025-26927CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to ...
CVE-2025-24297CRITICAL9.8Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces o...
CVE-2025-32778CRITICAL9.3Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screens...
CVE-2025-30727CRITICAL9.8Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported version...
CVE-2025-32445CRITICAL9.9Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify Eve...
CVE-2025-30206CRITICAL9.8Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service co...
CVE-2025-2567CRITICAL9.8An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling...
CVE-2025-28399CRITICAL9.8An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of...
CVE-2025-25456CRITICAL9.8Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
CVE-2025-22900CRITICAL9.8Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now