2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-26319CRITICAL9.8FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
CVE-2025-1958CRITICAL9.8A vulnerability, which was classified as critical, has been found in aaluoxiang oa_system 1.0. This issue affects some u...
CVE-2025-1956CRITICAL9.8A vulnerability classified as critical has been found in code-projects Shopping Portal 1.0. This affects an unknown part...
CVE-2025-26136CRITICAL9.8A SQL injection vulnerability exists in mysiteforme versions prior to 2025.01.1.
CVE-2025-1954CRITICAL9.8A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been declared as cri...
CVE-2025-1260CRITICAL9.1On affected platforms running Arista EOS with OpenConfig configured, a gNOI request can be run when it should have been ...
CVE-2025-1952CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Restaurant Table Booking System 1.0. Affected...
CVE-2025-1947CRITICAL9.8A vulnerability classified as critical has been found in hzmanyun Education and Training System 2.1.3. This affects the ...
CVE-2025-1946CRITICAL9.8A vulnerability was found in hzmanyun Education and Training System 2.1. It has been rated as critical. Affected by this...
CVE-2025-27507CRITICAL9The open-source identity infrastructure software Zitadel allows administrators to disable the user self-registration. ZI...
CVE-2025-1942CRITICAL9.8When String.toUpperCase() caused a string to get longer it was possible for uninitialized memory to be incorporated into...
CVE-2025-1941CRITICAL9.1Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been b...
CVE-2025-1906CRITICAL9.8A vulnerability has been found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. This vulner...
CVE-2025-1307CRITICAL9.8The Newscrunch theme for WordPress is vulnerable to arbitrary file uploads due to a missing capability check in the news...
CVE-2025-1903CRITICAL9.8A vulnerability was found in Codezips Online Shopping Website 1.0. It has been rated as critical. This issue affects som...
CVE-2025-1902CRITICAL9.8A vulnerability was found in PHPGurukul Student Record System 3.2. It has been declared as critical. This vulnerability ...
CVE-2025-1901CRITICAL9.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been classified as critical. This af...
CVE-2025-1900CRITICAL9.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this...
CVE-2025-0912CRITICAL9.8The Donations Widget plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3....
CVE-2025-1894CRITICAL9.8A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0. It has been rated as critical. Affected by ...
CVE-2025-1890CRITICAL9.8A vulnerability has been found in shishuocms 1.1 and classified as critical. This vulnerability affects the function han...
CVE-2025-26206CRITICAL9Cross Site Request Forgery vulnerability in sell done storefront v.1.0 allows a remote attacker to escalate privileges v...
CVE-2025-1889CRITICAL9.8picklescan before 0.0.22 only considers standard pickle file extensions in the scope for its vulnerability scan. An atta...
CVE-2025-1876CRITICAL9.8A vulnerability, which was classified as critical, has been found in D-Link DAP-1562 1.10. Affected by this issue is the...
CVE-2025-27270CRITICAL9.8Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now