2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-60089CRITICAL9.8Deserialization of Untrusted Data vulnerability in CRM Perks WP Gravity Forms FreshDesk Plugin gf-freshdesk allows Objec...
CVE-2025-60062CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer t...
CVE-2025-58951CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance S...
CVE-2025-58935CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-54723CRITICAL9.8Deserialization of Untrusted Data vulnerability in BoldThemes DentiCare denticare allows Object Injection.This issue aff...
CVE-2025-53433CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-68435CRITICAL9.1Zerobyte is a backup automation tool Zerobyte versions prior to 0.18.5 and 0.19.0 contain an authentication bypass vulne...
CVE-2025-68145CRITICAL9.1In mcp-server-git versions prior to 2025.12.17, when the server is started with the --repository flag to restrict operat...
CVE-2025-14833CRITICAL9.8A security flaw has been discovered in code-projects Online Appointment Booking System 1.0. The impacted element is an u...
CVE-2025-68118CRITICAL9.1FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.20.0, a vulnerability exists in Free...
CVE-2025-68114CRITICAL9.8Capstone is a disassembly framework. In versions 6.0.0-Alpha5 and prior, an unchecked vsnprintf return in SStream_concat...
CVE-2025-67791CRITICAL9.8An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 through 25.1.*. An incomplete co...
CVE-2025-14832CRITICAL9.8A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown funct...
CVE-2025-67793CRITICAL9.8An issue was discovered in DriveLock 24.1 through 24.1.*, 24.2 through 24.2.*, and 25.1 before 25.1.6. Users with the "M...
CVE-2025-67493CRITICAL9Homarr is an open-source dashboard. Prior to version 1.45.3, it was possible to craft an input which allowed privilege e...
CVE-2025-66647CRITICAL9.8RIOT is an open-source microcontroller operating system, designed to match the requirements of Internet of Things (IoT) ...
CVE-2025-43526CRITICAL9.8This issue was addressed with improved URL validation. This issue is fixed in Safari 26.2, macOS Tahoe 26.2. On a Mac wi...
CVE-2025-43428CRITICAL9.8A configuration issue was addressed with additional restrictions. This issue is fixed in iOS 26.2 and iPadOS 26.2, macOS...
CVE-2025-67787CRITICAL9.6An issue was discovered in 25.1.2 before 25.1.5. A Cross Site Scripting (XSS) issue in DriveLock Operations Center allow...
CVE-2025-67781CRITICAL9.9An issue was discovered in DriveLock 24.1 before 24.1.6, 24.2 before 24.2.7, and 25.1 before 25.1.5. Local unprivileged ...
CVE-2025-67073CRITICAL9.8A Buffer overflow vulnerability in function fromAdvSetMacMtuWan of bin httpd in Tenda AC10V4.0 V16.03.10.20 allows remot...
CVE-2025-34434CRITICAL9.1AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and dele...
CVE-2025-62521CRITICAL9.8ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code executio...
CVE-2025-67165CRITICAL9.8An Insecure Direct Object Reference (IDOR) in Pagekit CMS v1.0.18 allows attackers to escalate privileges.
CVE-2025-67164CRITICAL9.9An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows att...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now