2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27816CRITICAL9.8A vulnerability was discovered in the Arctera InfoScale 7.0 through 8.0.2 where a .NET remoting endpoint can be exploite...
CVE-2025-1475CRITICAL9.8The WPCOM Member plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.7.5...
CVE-2025-27796CRITICAL9.8ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds acc...
CVE-2025-2067CRITICAL9.8A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue a...
CVE-2025-2066CRITICAL9.8A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vu...
CVE-2025-2065CRITICAL9.8A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This...
CVE-2025-2064CRITICAL9.8A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0....
CVE-2025-2063CRITICAL9.8A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this...
CVE-2025-2062CRITICAL9.8A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is...
CVE-2025-2060CRITICAL9.8A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This ...
CVE-2025-2059CRITICAL9.8A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by th...
CVE-2025-2058CRITICAL9.8A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected ...
CVE-2025-2057CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affect...
CVE-2025-2050CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3....
CVE-2025-2046CRITICAL9.8A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by ...
CVE-2025-2041CRITICAL9.8A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected b...
CVE-2025-25763CRITICAL9.8crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVE-2025-2036CRITICAL9.8A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects a...
CVE-2025-27509CRITICAL9.3fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could ...
CVE-2025-25361CRITICAL9.8An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 all...
CVE-2025-2035CRITICAL9.8A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue ...
CVE-2025-2034CRITICAL9.8A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by th...
CVE-2025-25632CRITICAL9.8Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
CVE-2025-25362CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via...
CVE-2025-27517CRITICAL9.3Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lea...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now