2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-28100CRITICAL9.8A SQL Injection vulnerability in dingfanzuCMS v.1.0 allows a attacker to execute arbitrary code via not filtering the co...
CVE-2025-32911CRITICAL9A use-after-free type vulnerability was found in libsoup, in the soup_message_headers_get_content_disposition() function...
CVE-2025-28137CRITICAL9.8The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th...
CVE-2025-30985CRITICAL9.8Deserialization of Untrusted Data vulnerability in kagla GNUCommerce gnucommerce allows Object Injection.This issue affe...
CVE-2025-3579CRITICAL9.3In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute una...
CVE-2025-3578CRITICAL9.3A malicious, authenticated user in Aidex, versions prior to 1.7, could list credentials of other users, create or modify...
CVE-2025-32428CRITICAL9Jupyter Remote Desktop Proxy allows you to run a Linux Desktop on a JupyterHub. jupyter-remote-desktop-proxy was meant t...
CVE-2025-24797CRITICAL9.8Meshtastic is an open source mesh networking solution. A fault in the handling of mesh packets containing invalid protob...
CVE-2025-3593CRITICAL9.8A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been declared as critical. This vulnerab...
CVE-2025-3589CRITICAL9.8A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affect...
CVE-2025-1782CRITICAL9.9In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used...
CVE-2025-3277CRITICAL9.8An integer overflow can be triggered in SQLite’s `concat_ws()` function. The resulting, truncated integer is then used t...
CVE-2025-32931CRITICAL9.1DevDojo Voyager 1.4.0 through 1.8.0, when Laravel 8 or later is used, allows authenticated administrators to execute arb...
CVE-2025-22372CRITICAL9.3Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are ei...
CVE-2025-22371CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (S...
CVE-2025-3559CRITICAL9.8A vulnerability has been found in ghostxbh uzy-ssm-mall 1.0.0 and classified as critical. This vulnerability affects the...
CVE-2025-3558CRITICAL9.8A vulnerability, which was classified as critical, was found in ghostxbh uzy-ssm-mall 1.0.0. This affects an unknown par...
CVE-2025-3553CRITICAL9.8A vulnerability was found in phpshe 1.8. It has been declared as critical. This vulnerability affects the function pe_de...
CVE-2025-0129CRITICAL9.3An improper exception check in Palo Alto Networks Prisma Access Browser allows a low privileged user to prevent Prisma A...
CVE-2025-3439CRITICAL9.8The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is ...
CVE-2025-23391CRITICAL9.1A Incorrect Privilege Assignment vulnerability in SUSE rancher allows a Restricted Administrator to change the password ...
CVE-2025-32607CRITICAL9.8Deserialization of Untrusted Data vulnerability in magepeopleteam WpBookingly service-booking-manager allows Object Inje...
CVE-2025-32603CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in HK WP Online Users...
CVE-2025-32579CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in SoftClever Limited Sync Posts sync-posts allows Upload ...
CVE-2025-32577CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now