2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-30510CRITICAL9.8An attacker can upload an arbitrary file instead of a plant image.
CVE-2025-26927CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes AI Hub aihub allows Upload a Web Shell to ...
CVE-2025-24297CRITICAL9.8Due to lack of server-side input validation, attackers can inject malicious JavaScript code into users personal spaces o...
CVE-2025-32778CRITICAL9.3Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screens...
CVE-2025-30727CRITICAL9.8Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported version...
CVE-2025-32445CRITICAL9.9Argo Events is an event-driven workflow automation framework for Kubernetes. A user with permission to create/modify Eve...
CVE-2025-30206CRITICAL9.8Dpanel is a Docker visualization panel system which provides complete Docker management functions. The Dpanel service co...
CVE-2025-2567CRITICAL9.8An attacker could modify or disable settings, disrupt fuel monitoring and supply chain operations, leading to disabling...
CVE-2025-28399CRITICAL9.8An issue in Erick xmall v.1.1 and before allows a remote attacker to escalate privileges via the updateAddress method of...
CVE-2025-25456CRITICAL9.8Tenda AC10 V4.0si_V16.03.10.20 is vulnerable to Buffer Overflow in AdvSetMacMtuWan via mac2.
CVE-2025-22900CRITICAL9.8Totolink N600R v4.3.0cu.7647_B20210106 was discovered to contain a stack overflow via the macCloneMac parameter in the s...
CVE-2025-28100CRITICAL9.8A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the co...
CVE-2025-32911CRITICAL9A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function...
CVE-2025-28137CRITICAL9.8The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th...
CVE-2025-30985CRITICAL9.8Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affe...
CVE-2025-3579CRITICAL9.3In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute una...
CVE-2025-3578CRITICAL9.3A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify...
CVE-2025-32428CRITICAL9Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant t...
CVE-2025-24797CRITICAL9.8Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protob...
CVE-2025-3593CRITICAL9.8A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerab...
CVE-2025-3589CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affect...
CVE-2025-1782CRITICAL9.9In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used...
CVE-2025-3277CRITICAL9.8An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used t...
CVE-2025-32931CRITICAL9.1DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arb...
CVE-2025-22372CRITICAL9.3Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are ei...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now