2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-2199CRITICAL9.3SQL injection vulnerability in the Innovación y Cualificación local administration plugin ajax.php. This vulnerability a...
CVE-2025-2370CRITICAL9.8A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been declared as critical. Affected b...
CVE-2025-2369CRITICAL9.8A vulnerability was found in TOTOLINK EX1800T up to 9.1.0cu.2112_B20220316. It has been classified as critical. Affected...
CVE-2025-2395CRITICAL9.8The U-Office Force from e-Excellence has an Improper Authentication vulnerability, allowing unauthenticated remote attac...
CVE-2025-2363CRITICAL9.8A vulnerability classified as critical has been found in lenve VBlog up to 1.0.0. Affected is the function uploadImg of ...
CVE-2025-2362CRITICAL9.8A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affe...
CVE-2025-2360CRITICAL9.8A vulnerability classified as critical was found in D-Link DIR-823G 1.0.2B05_20181207. Affected by this vulnerability is...
CVE-2025-2359CRITICAL9.8A vulnerability classified as critical has been found in D-Link DIR-823G 1.0.2B05_20181207. Affected is the function Set...
CVE-2025-2345CRITICAL9.8A vulnerability, which was classified as very critical, was found in IROAD Dash Cam X5 and Dash Cam X6 up to 20250308. T...
CVE-2025-2334CRITICAL9.1A vulnerability classified as problematic has been found in 274056675 springboot-openai-chatgpt e84f6f5. This affects th...
CVE-2025-26875CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 M...
CVE-2025-2322CRITICAL9.8A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affec...
CVE-2025-1771CRITICAL9.8The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via t...
CVE-2025-2320CRITICAL9.8A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by th...
CVE-2025-29775CRITICAL9.3xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab...
CVE-2025-29774CRITICAL9.3xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab...
CVE-2025-29386CRITICAL9.8In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, w...
CVE-2025-29385CRITICAL9.8In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerabil...
CVE-2025-29384CRITICAL9.8In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability...
CVE-2025-29031CRITICAL9.8Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
CVE-2025-29030CRITICAL9.8Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2025-29029CRITICAL9.8Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
CVE-2025-2304CRITICAL9.4A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the ...
CVE-2025-2000CRITICAL9.8A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation...
CVE-2025-27595CRITICAL9.8The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculat...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now