2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-3137CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Aff...
CVE-2025-3135CRITICAL9.8A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerabili...
CVE-2025-3120CRITICAL9.8A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. Thi...
CVE-2025-3119CRITICAL9.8A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerabilit...
CVE-2025-31484CRITICAL9.3conda-forge infrastructure holds common configurations and settings for key pieces of the conda-forge infrastructure. Be...
CVE-2025-31477CRITICAL9.8The Tauri shell plugin allows access to the system shell. Prior to 2.2.1, the Tauri shell plugin exposes functionality t...
CVE-2025-3118CRITICAL9.8A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an...
CVE-2025-29085CRITICAL9.8SQL injection vulnerability in vipshop Saturn v.3.5.1 and before allows a remote attacker to execute arbitrary code via ...
CVE-2025-29063CRITICAL9.8An issue in BL-AC2100 V1.0.4 and before allows a remote attacker to execute arbitrary code via the enable parameter pass...
CVE-2025-29062CRITICAL9.8An issue in BL-AC2100 <=V1.0.4 allows a remote attacker to execute arbitrary code via the time1 and time2 parameters in ...
CVE-2025-31286CRITICAL9An HTML injection vulnerability previously discovered in Trend Vision One could have allowed a malicious user to execute...
CVE-2025-2005CRITICAL9.8The Front End Users plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-0415CRITICAL9.2A remote attacker with web administrator privileges can exploit the device’s web interface to execute arbitrary system c...
CVE-2025-30356CRITICAL9.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-31612CRITICAL9.8Deserialization of Untrusted Data vulnerability in Sabuj Kundu CBX Poll cbxpoll allows Object Injection.This issue affec...
CVE-2025-31579CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in EXEIdeas Internati...
CVE-2025-31553CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced...
CVE-2025-31552CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in davidfcarr RSVPMar...
CVE-2025-31551CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Salesmate.io Sales...
CVE-2025-31534CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in shopperdotcom Shop...
CVE-2025-31531CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in click5 History Log...
CVE-2025-30841CRITICAL9.9Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in adamskaat Countdown & Cl...
CVE-2025-30807CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martin Nguyen Next...
CVE-2025-30580CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in kellydiek DigiWidgets Image Editor digiwidget...
CVE-2025-3096CRITICAL9.3Clinic’s Patient Management System versions 2.0 suffers from a SQL injection vulnerability in the login page.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now