2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25176CRITICAL9.1Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in ...
CVE-2025-69992CRITICAL9.8phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of a...
CVE-2025-69991CRITICAL9.8phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
CVE-2025-69990CRITICAL9.1phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file ...
CVE-2025-68811CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc...
CVE-2025-68809CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd...
CVE-2025-68794CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-al...
CVE-2025-68775CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations le...
CVE-2025-65783CRITICAL9.8An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2....
CVE-2025-12548CRITICAL9A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe...
CVE-2025-11250CRITICAL9.1Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper fi...
CVE-2025-40805CRITICAL10Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe...
CVE-2025-14829CRITICAL9.1The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient ...
CVE-2025-10915CRITICAL9.8The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check...
CVE-2025-67146CRITICAL9.4Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)...
CVE-2025-29329CRITICAL9.8Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ...
CVE-2025-12420CRITICAL9.8A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona...
CVE-2025-67147CRITICAL9.8Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a...
CVE-2025-66802CRITICAL9.8Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive...
CVE-2025-51567CRITICAL9.1A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a...
CVE-2025-68472CRITICAL9.1MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti...
CVE-2025-63314CRITICAL10A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a...
CVE-2025-46070CRITICAL9.8An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon...
CVE-2025-46066CRITICAL9.9An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
CVE-2025-65552CRITICAL9.8D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now