2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-15194CRITICAL9.8A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality ...
CVE-2025-68929CRITICAL9Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec...
CVE-2025-65570CRITICAL9.8A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof”...
CVE-2025-57460CRITICAL9.8File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
CVE-2025-15186CRITICAL9.8A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unkno...
CVE-2025-15185CRITICAL9.8A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown ...
CVE-2025-15184CRITICAL9.8A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the...
CVE-2025-15183CRITICAL9.8A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown ...
CVE-2025-15182CRITICAL9.8A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of ...
CVE-2025-15181CRITICAL9.8A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unkn...
CVE-2025-15228CRITICAL9.8BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remot...
CVE-2025-15226CRITICAL9.8WMPro developed by Sunnet has a Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload...
CVE-2025-15069CRITICAL9.8Improper Authentication vulnerability in Gmission Web Fax allows Privilege Escalation.This issue affects Web Fax: from 3...
CVE-2025-15068CRITICAL9.8Missing Authorization vulnerability in Gmission Web Fax allows Authentication Abuse, Session Credential Falsification th...
CVE-2025-52691CRITICAL10Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any lo...
CVE-2025-15168CRITICAL9.8A vulnerability was identified in itsourcecode Student Management System 1.0. Affected is an unknown function of the fil...
CVE-2025-15167CRITICAL9.8A vulnerability was determined in itsourcecode Online Cake Ordering System 1.0. This impacts an unknown function of the ...
CVE-2025-15166CRITICAL9.8A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown function of the file ...
CVE-2025-15165CRITICAL9.8A vulnerability has been found in itsourcecode Online Cake Ordering System 1.0. The impacted element is an unknown funct...
CVE-2025-15127CRITICAL9.8A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0....
CVE-2025-54322CRITICAL9.8Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid paramete...
CVE-2025-68952CRITICAL9.8Eigent is a multi-agent Workforce. In version 0.0.60, a 1-click Remote Code Execution (RCE) vulnerability has been ident...
CVE-2025-68932CRITICAL9.8FreshRSS is a free, self-hostable RSS aggregator. Prior to version 1.28.0, FreshRSS uses cryptographically weak random n...
CVE-2025-66203CRITICAL9.1StreamVault is a video download integration solution. Prior to version 251126, a Remote Code Execution (RCE) vulnerabili...
CVE-2025-68668CRITICAL9.9n8n is an open source workflow automation platform. From version 1.0.0 to before 2.0.0, a sandbox bypass vulnerability e...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now