2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-26853CRITICAL9.8DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 has a broken authorization schema.
CVE-2025-26852CRITICAL9.8DESCOR INFOCAD 3.5.1 and before and fixed in v.3.5.2.0 allows SQL Injection.
CVE-2025-29980CRITICAL9.8A SQL injection issue has been discovered in eTRAKiT.net release 3.2.1.77. Due to improper input validation, a remote un...
CVE-2025-29922CRITICAL9.6kcp is a Kubernetes-like control plane for form-factors and use-cases beyond Kubernetes and container workloads. Prior t...
CVE-2025-29411CRITICAL9.8An arbitrary file upload vulnerability in the Client Profile Update section of Mart Developers iBanking v2.0.0 allows at...
CVE-2025-2311CRITICAL9Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials ...
CVE-2025-2505CRITICAL9.8The Age Gate plugin for WordPress is vulnerable to Local PHP File Inclusion in all versions up to, and including, 3.5.3 ...
CVE-2025-27786CRITICAL9.1Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file removal in core.py. ...
CVE-2025-27783CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in train.py. T...
CVE-2025-27782CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to arbitrary file write in inference.p...
CVE-2025-27781CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in inference...
CVE-2025-27780CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_inf...
CVE-2025-27779CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_bl...
CVE-2025-27778CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py...
CVE-2025-29926CRITICAL9.8XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager ...
CVE-2025-29783CRITICAL9vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Moo...
CVE-2025-29401CRITICAL9.8An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execut...
CVE-2025-29137CRITICAL9.8Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set f...
CVE-2025-2512CRITICAL9.8The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing...
CVE-2025-30139CRITICAL9.8An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts ...
CVE-2025-30137CRITICAL9.8An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The ...
CVE-2025-24799CRITICAL9.8GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the...
CVE-2025-21619CRITICAL9.8GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the ru...
CVE-2025-25595CRITICAL9.8A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a bru...
CVE-2025-30132CRITICAL9.1An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, cr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now