2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-0532CRITICAL9.8A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unkn...
CVE-2025-0527CRITICAL9.8A vulnerability classified as critical was found in code-projects Admission Management System 1.0. Affected by this vuln...
CVE-2025-23922CRITICAL10Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a W...
CVE-2025-23797CRITICAL9.8Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Options Editor wp-options-editor allows Privilege Es...
CVE-2025-0471CRITICAL9.8Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability coul...
CVE-2025-22916CRITICAL9.8RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function.
CVE-2025-22913CRITICAL9.8RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function.
CVE-2025-22912CRITICAL9.8RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
CVE-2025-22907CRITICAL9.8RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function.
CVE-2025-22906CRITICAL9.8RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN...
CVE-2025-22905CRITICAL9.8RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
CVE-2025-22904CRITICAL9.8RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function.
CVE-2025-0456CRITICAL9.8The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attac...
CVE-2025-0455CRITICAL9.8The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i...
CVE-2025-0491CRITICAL9.8A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown fun...
CVE-2025-0487CRITICAL9.8A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some...
CVE-2025-0486CRITICAL9.8A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been declared as critical. Affected by this vulnerabil...
CVE-2025-22146CRITICAL9.1Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in t...
CVE-2025-0502CRITICAL9.1Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS...
CVE-2025-22968CRITICAL9.8An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account witho...
CVE-2025-22785CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course B...
CVE-2025-22782CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-...
CVE-2025-23061CRITICAL9.8Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO...
CVE-2025-21311CRITICAL9.8Windows NTLM V1 Elevation of Privilege Vulnerability
CVE-2025-21307CRITICAL9.8Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now