2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66205CRITICAL9.8Frappe is a full-stack web application framework. Prior to 15.86.0 and 14.99.2, a certain endpoint was vulnerable to err...
CVE-2025-65836CRITICAL9.1PublicCMS V5.202506.b is vulnerable to SSRF. in the chat interface of SimpleAiAdminController.
CVE-2025-51683CRITICAL9.8A blind SQL Injection (SQLi) vulnerability in mJobtime v15.7.2 allows unauthenticated attackers to execute arbitrary SQL...
CVE-2025-51682CRITICAL9.8mJobtime 15.7.2 handles authorization on the client side, which allows an attacker to modify the client-side code and ga...
CVE-2025-3500CRITICAL9.8Integer Overflow or Wraparound vulnerability in Avast Antivirus (25.1.981.6) on Windows allows Privilege Escalation.This...
CVE-2025-63531CRITICAL9.8A SQL injection vulnerability exists in the Blood Bank Management System 1.0 within the receiverLogin.php component. The...
CVE-2025-12106CRITICAL9.1Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-...
CVE-2025-13815CRITICAL9.8A weakness has been identified in moxi159753 Mogu Blog v2 up to 5.2. The affected element is an unknown function of the ...
CVE-2025-13814CRITICAL9.8A security flaw has been discovered in moxi159753 Mogu Blog v2 up to 5.2. Impacted is the function LocalFileServiceImpl....
CVE-2025-13806CRITICAL9.8A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of ...
CVE-2025-13800CRITICAL9.8A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the...
CVE-2025-13799CRITICAL9.8A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_...
CVE-2025-13798CRITICAL9.8A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_o...
CVE-2025-13797CRITICAL9.8A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifim...
CVE-2025-35028CRITICAL9.1By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecu...
CVE-2025-13788CRITICAL9.8A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /t...
CVE-2025-13787CRITICAL9.1A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/...
CVE-2025-13786CRITICAL9.8A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fe...
CVE-2025-13783CRITICAL9.8A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the fun...
CVE-2025-13782CRITICAL9.8A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is...
CVE-2025-13615CRITICAL9.8The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin...
CVE-2025-66216CRITICAL9.8AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been ident...
CVE-2025-66219CRITICAL9.8willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm...
CVE-2025-66034CRITICAL9.8fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttool...
CVE-2025-65112CRITICAL9.8PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubN...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now