2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12913CRITICAL9.8A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomde...
CVE-2025-64486CRITICAL9.3calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary ass...
CVE-2025-10230CRITICAL10A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a ...
CVE-2025-12873CRITICAL9.8A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a...
CVE-2025-3222CRITICAL9.3Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue ...
CVE-2025-12862CRITICAL9.8A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow...
CVE-2025-63691CRITICAL9.6In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the...
CVE-2025-63690CRITICAL9.1In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the sy...
CVE-2025-63689CRITICAL10Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e...
CVE-2025-52425CRITICAL9.8An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to e...
CVE-2025-34299CRITICAL9.8Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This fl...
CVE-2025-12857CRITICAL9.8A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow...
CVE-2025-12856CRITICAL9.8A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /...
CVE-2025-12855CRITICAL9.8A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi...
CVE-2025-12853CRITICAL9.8A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele...
CVE-2025-10870CRITICAL9.3SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete datab...
CVE-2025-64338CRITICAL9ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular use...
CVE-2025-12352CRITICAL9.8The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-64180CRITICAL10Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vul...
CVE-2025-11546CRITICAL9.3CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, C...
CVE-2025-62630CRITICAL9.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories...
CVE-2025-59171CRITICAL9.8Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories...
CVE-2025-12488CRITICAL9.8oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This...
CVE-2025-12487CRITICAL9.8oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This...
CVE-2025-27918CRITICAL9.8An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now