2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2641 | CRITICAL | 9.8 | 0.5% | Mar 23, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affec... |
| CVE-2025-2640 | CRITICAL | 9.8 | 0.5% | Mar 23, 2025 | A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue ... |
| CVE-2025-2628 | CRITICAL | 9.8 | 0.4% | Mar 22, 2025 | A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected i... |
| CVE-2025-2627 | CRITICAL | 9.8 | 0.4% | Mar 22, 2025 | A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. This ... |
| CVE-2025-2626 | CRITICAL | 9.8 | 0.4% | Mar 22, 2025 | A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Th... |
| CVE-2025-2621 | CRITICAL | 9.8 | 1.9% | Mar 22, 2025 | A vulnerability was found in D-Link DAP-1620 1.03 and classified as critical. This issue affects the function check_dws_... |
| CVE-2025-2620 | CRITICAL | 9.8 | 7.5% | Mar 22, 2025 | A vulnerability has been found in D-Link DAP-1620 1.03 and classified as critical. This vulnerability affects the functi... |
| CVE-2025-2619 | CRITICAL | 9.8 | 1.8% | Mar 22, 2025 | A vulnerability, which was classified as critical, was found in D-Link DAP-1620 1.03. This affects the function check_dw... |
| CVE-2025-2618 | CRITICAL | 9.8 | 1.8% | Mar 22, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DAP-1620 1.03. Affected by this issue is the... |
| CVE-2025-30472 | CRITICAL | 9.8 | 0.4% | Mar 22, 2025 | Corosync through 3.1.9, if encryption is disabled or the attacker knows the encryption key, has a stack-based buffer ove... |
| CVE-2025-29927 | CRITICAL | 9.1 | 99.6% | Mar 21, 2025 | Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions ... |
| CVE-2025-2589 | CRITICAL | 9.8 | 0.4% | Mar 21, 2025 | A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue... |
| CVE-2025-26336 | CRITICAL | 9.8 | 0.6% | Mar 21, 2025 | Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell ... |
| CVE-2025-2538 | CRITICAL | 9.8 | 0.5% | Mar 20, 2025 | A hardcoded credential vulnerability exists in a specific deployment pattern for Esri Portal for ArcGIS versions 11.4 an... |
| CVE-2025-26853 | CRITICAL | 9.8 | 0.4% | Mar 20, 2025 | DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema. |
| CVE-2025-26852 | CRITICAL | 9.8 | 0.4% | Mar 20, 2025 | DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection. |
| CVE-2025-29980 | CRITICAL | 9.8 | 0.5% | Mar 20, 2025 | A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote un... |
| CVE-2025-29922 | CRITICAL | 9.6 | 0.3% | Mar 20, 2025 | kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t... |
| CVE-2025-29411 | CRITICAL | 9.8 | 0.6% | Mar 20, 2025 | An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows at... |
| CVE-2025-2311 | CRITICAL | 9 | 0.2% | Mar 20, 2025 | Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials ... |
| CVE-2025-2505 | CRITICAL | 9.8 | 1.2% | Mar 20, 2025 | The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 ... |
| CVE-2025-27786 | CRITICAL | 9.1 | 0.5% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. ... |
| CVE-2025-27783 | CRITICAL | 9.8 | 1.0% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. T... |
| CVE-2025-27782 | CRITICAL | 9.8 | 1.3% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.p... |
| CVE-2025-27781 | CRITICAL | 9.8 | 0.8% | Mar 19, 2025 | Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now