2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-36747CRITICAL9.8ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish ...
CVE-2025-14620CRITICAL9.8A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno...
CVE-2025-14619CRITICAL9.8A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-14590CRITICAL9.8A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown functio...
CVE-2025-14588CRITICAL9.8A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown co...
CVE-2025-14587CRITICAL9.8A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of th...
CVE-2025-14586CRITICAL9.8A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprint...
CVE-2025-14440CRITICAL9.8The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2...
CVE-2025-11693CRITICAL9.8The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers...
CVE-2025-10738CRITICAL9.8The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ paramet...
CVE-2025-14585CRITICAL9.8A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functi...
CVE-2025-14584CRITICAL9.8A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /a...
CVE-2025-14583CRITICAL9.8A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /a...
CVE-2025-14611CRITICAL9.8Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of th...
CVE-2025-14578CRITICAL9.8A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown functio...
CVE-2025-14571CRITICAL9.8A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u...
CVE-2025-14570CRITICAL9.8A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-66430CRITICAL9.1Plesk 18.0 has Incorrect Access Control.
CVE-2025-65854CRITICAL9.8Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and...
CVE-2025-14566CRITICAL9.8A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ...
CVE-2025-14565CRITICAL9.8A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec...
CVE-2025-54947CRITICAL9.8In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists...
CVE-2025-58130CRITICAL9.1Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11...
CVE-2025-67728CRITICAL9.8Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau...
CVE-2025-67727CRITICAL9.8Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now