2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27780CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in model_inf...
CVE-2025-27779CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `model_bl...
CVE-2025-27778CRITICAL9.8Applio is a voice conversion tool. Versions 3.2.8-bugfix and prior are vulnerable to unsafe deserialization in `infer.py...
CVE-2025-29926CRITICAL9.8XWiki Platform is a generic wiki platform. Prior to 15.10.15, 16.4.6, and 16.10.0, any user can exploit the WikiManager ...
CVE-2025-29783CRITICAL9vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. When vLLM is configured to use Moo...
CVE-2025-29401CRITICAL9.8An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execut...
CVE-2025-29137CRITICAL9.8Tenda AC7 V1.0 V15.03.06.44 found a buffer overflow caused by the timeZone parameter in the form_fast_setting_wifi_set f...
CVE-2025-2512CRITICAL9.8The File Away plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check and missing...
CVE-2025-30139CRITICAL9.8An issue was discovered on G-Net Dashcam BB GONX devices. Default credentials for SSID cannot be changed. It broadcasts ...
CVE-2025-30137CRITICAL9.8An issue was discovered in the G-Net GNET APK 2.6.2. Hardcoded credentials exist in in APK for ports 9091 and 9092. The ...
CVE-2025-24799CRITICAL9.8GLPI is a free asset and IT management software package. An unauthenticated user can perform a SQL injection through the...
CVE-2025-21619CRITICAL9.8GLPI is a free asset and IT management software package. An administrator user can perfom a SQL injection through the ru...
CVE-2025-25595CRITICAL9.8A lack of rate limiting in the login page of Safe App version a3.0.9 allows attackers to bypass authentication via a bru...
CVE-2025-30132CRITICAL9.1An issue was discovered on IROAD Dashcam V devices. It uses an unregistered public domain name as an internal domain, cr...
CVE-2025-30123CRITICAL9.8An issue was discovered on ROADCAM X3 devices. The mobile app APK (Viidure) contains hardcoded FTP credentials for the F...
CVE-2025-30122CRITICAL9.8An issue was discovered on ROADCAM X3 devices. It has a uniform default credential set that cannot be modified by users,...
CVE-2025-30115CRITICAL9.8An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Default Credentials Cannot Be Changed. It use...
CVE-2025-30114CRITICAL9.1An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Bypassing of Device Pairing can occur. The pa...
CVE-2025-30113CRITICAL9.8An issue was discovered on the Forvia Hella HELLA Driving Recorder DR 820. Hardcoded Credentials exist in the APK for Po...
CVE-2025-2494CRITICAL9.8Unrestricted file upload to Softdial Contact Center of Sytel Ltd. This vulnerability could allow an attacker to upload f...
CVE-2025-2473CRITICAL9.8A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by th...
CVE-2025-2472CRITICAL9.8A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affect...
CVE-2025-29913CRITICAL9.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-29912CRITICAL9.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...
CVE-2025-29911CRITICAL9.8CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDL...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now