2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66222CRITICAL9.6DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting...
CVE-2025-66208CRITICAL9.8Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing ...
CVE-2025-66032CRITICAL9.8Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor...
CVE-2025-64443CRITICAL9.6MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gatew...
CVE-2025-34319CRITICAL9.3TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai...
CVE-2025-55182CRITICAL10A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1...
CVE-2025-65267CRITICAL9In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to...
CVE-2025-13390CRITICAL9.8The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1...
CVE-2025-13342CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress ...
CVE-2025-13486CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr...
CVE-2025-13658CRITICAL9.3A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e...
CVE-2025-13542CRITICAL9.8The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-13510CRITICAL9.3The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio...
CVE-2025-66409CRITICAL9.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earli...
CVE-2025-65896CRITICAL9.8SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via craf...
CVE-2025-60736CRITICAL9.8code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.
CVE-2025-60854CRITICAL9.8A vulnerability has been found in D-Link R15 (AX1500) 1.20.01 and below. By manipulating the model name parameter during...
CVE-2025-58386CRITICAL9.8In Terminalfour 8 through 8.4.1.1, the userLevel parameter in the user management function is not subject to proper serv...
CVE-2025-65656CRITICAL9.8dcat-admin v2.2.3-beta and before is vulnerable to file inclusion in admin/src/Extend/VersionManager.php.
CVE-2025-65358CRITICAL9.8Edoc-doctor-appointment-system v1.0.1 was discovered to contain SQl injection vulnerability via the 'docid' parameter at...
CVE-2025-13828CRITICAL9SummaryA non privileged user can install and remove arbitrary packages via composer for a composer based installed, even...
CVE-2025-59703CRITICAL9.1Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-59695CRITICAL9.8Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (...
CVE-2025-59693CRITICAL9.8The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patch...
CVE-2025-41013CRITICAL9.8SQL injection vulnerability in TCMAN GIM v11 in version 20250304. This vulnerability allows an attacker to retrieve, cre...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now