2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-2058CRITICAL9.8A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected ...
CVE-2025-2057CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affect...
CVE-2025-2050CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3....
CVE-2025-2046CRITICAL9.8A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by ...
CVE-2025-2041CRITICAL9.8A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected b...
CVE-2025-25763CRITICAL9.8crmeb CRMEB-KY v5.4.0 and before has a SQL Injection vulnerability at getRead() in /system/SystemDatabackupServices.php
CVE-2025-2036CRITICAL9.8A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects a...
CVE-2025-27509CRITICAL9.3fleetdm/fleet is an open source device management, built on osquery. In vulnerable versions of Fleet, an attacker could ...
CVE-2025-25361CRITICAL9.8An arbitrary file upload vulnerability in the component /cms/CmsWebFileAdminController.java of PublicCMS v4.0.202406 all...
CVE-2025-2035CRITICAL9.8A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0 and classified as critical. Affected by this issue ...
CVE-2025-2034CRITICAL9.8A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by th...
CVE-2025-25632CRITICAL9.8Tenda AC15 v15.03.05.19 is vulnerable to Command Injection via the handler function in /goform/telnet.
CVE-2025-25362CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via...
CVE-2025-27517CRITICAL9.3Volt is an elegantly crafted functional API for Livewire. Malicious, user-crafted request payloads could potentially lea...
CVE-2025-27515CRITICAL9.8Laravel is a web application framework. When using wildcard validation to validate a given file or image field (`files.*...
CVE-2025-25015CRITICAL9.9Prototype pollution in Kibana leads to arbitrary code execution via a crafted file upload and specifically crafted HTTP ...
CVE-2025-1515CRITICAL9.8The WP Real Estate Manager plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ...
CVE-2025-1393CRITICAL9.8An unauthenticated remote attacker can use hard-coded credentials to gain full administration privileges on the affected...
CVE-2025-27682CRITICAL9.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Per...
CVE-2025-27681CRITICAL9.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter...
CVE-2025-27680CRITICAL9.1Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmwar...
CVE-2025-27678CRITICAL9.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote C...
CVE-2025-27677CRITICAL9.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links ...
CVE-2025-27675CRITICAL9.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Vulnerable Open...
CVE-2025-27674CRITICAL9.8Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Hardcoded IdP K...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now