2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-2641CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affec...
CVE-2025-2640CRITICAL9.8A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue ...
CVE-2025-2628CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected i...
CVE-2025-2627CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. This ...
CVE-2025-2626CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Th...
CVE-2025-2621CRITICAL9.8A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_...
CVE-2025-2620CRITICAL9.8A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the functi...
CVE-2025-2619CRITICAL9.8A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dw...
CVE-2025-2618CRITICAL9.8A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the...
CVE-2025-30472CRITICAL9.8Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer ove...
CVE-2025-29927CRITICAL9.1Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions ...
CVE-2025-2589CRITICAL9.8A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue...
CVE-2025-26336CRITICAL9.8Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell ...
CVE-2025-2538CRITICAL9.8A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 an...
CVE-2025-26853CRITICAL9.8DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
CVE-2025-26852CRITICAL9.8DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.
CVE-2025-29980CRITICAL9.8A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote un...
CVE-2025-29922CRITICAL9.6kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t...
CVE-2025-29411CRITICAL9.8An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows at...
CVE-2025-2311CRITICAL9Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials ...
CVE-2025-2505CRITICAL9.8The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 ...
CVE-2025-27786CRITICAL9.1Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. ...
CVE-2025-27783CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. T...
CVE-2025-27782CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.p...
CVE-2025-27781CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now