2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-13023CRITICAL9.8Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F...
CVE-2025-13022CRITICAL9.8Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder...
CVE-2025-13021CRITICAL9.8Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder...
CVE-2025-8324CRITICAL9.8Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the ...
CVE-2025-12539CRITICAL10The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up...
CVE-2025-12813CRITICAL9.8The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i...
CVE-2025-11457CRITICAL9.8The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privile...
CVE-2025-11170CRITICAL9.8The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation...
CVE-2025-42890CRITICAL10SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended use...
CVE-2025-42887CRITICAL9.9Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal...
CVE-2025-11892CRITICAL9.6An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross...
CVE-2025-64513CRITICAL9.3Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a...
CVE-2025-12480CRITICAL9.1Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init...
CVE-2025-12939CRITICAL9.8A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is s...
CVE-2025-12938CRITICAL9.8A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknow...
CVE-2025-12933CRITICAL9.8A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatew...
CVE-2025-12932CRITICAL9.8A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functional...
CVE-2025-12931CRITICAL9.8A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown funct...
CVE-2025-12930CRITICAL9.8A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /...
CVE-2025-12929CRITICAL9.8A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user o...
CVE-2025-12928CRITICAL9.8A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file...
CVE-2025-12868CRITICAL9.8New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated ...
CVE-2025-12866CRITICAL9.8EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote...
CVE-2025-12925CRITICAL9.8A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the func...
CVE-2025-12916CRITICAL9.8A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now