2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12476CRITICAL9.8Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-63622CRITICAL9.8A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the ...
CVE-2025-4665CRITICAL9.6WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injectio...
CVE-2025-64095CRITICAL9.8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-62368CRITICAL9Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerabilit...
CVE-2025-43017CRITICAL9.8HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which ...
CVE-2025-61235CRITICAL9.1An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,...
CVE-2025-12424CRITICAL9.8Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-60355CRITICAL9.8zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2025-12422CRITICAL9.8Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affec...
CVE-2025-36386CRITICAL9.8IBM Maximo Application Suite 9.0.0 through 9.0.15 and 9.1.0 through 9.1.4 could allow a remote attacker to bypass authen...
CVE-2025-61128CRITICAL9.1Stack-based buffer overflow vulnerability in WAVLINK QUANTUM D3G/WL-WN530HG3 firmware M30HG3_V240730, and possibly other...
CVE-2025-61043CRITICAL9.1An out-of-bounds read vulnerability has been discovered in Monkey's Audio 11.31, specifically in the CAPECharacterHelper...
CVE-2025-12380CRITICAL9.8Starting with Firefox 142, it was possible for a compromised child process to trigger a use-after-free in the GPU or bro...
CVE-2025-9313CRITICAL9.3An unauthenticated user can connect to a publicly accessible database using arbitrary credentials. The system grants ful...
CVE-2025-40074CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: ipv4: start using dst_dev_rcu() Change icmpv4_xrli...
CVE-2025-12378CRITICAL9.8A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This issue affects some unknown pr...
CVE-2025-12339CRITICAL9.8A security vulnerability has been detected in Campcodes Retro Basketball Shoes Online Store 1.0. This issue affects some...
CVE-2025-12338CRITICAL9.8A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. This vulnerability affects unknown ...
CVE-2025-12337CRITICAL9.8A security flaw has been discovered in Campcodes Retro Basketball Shoes Online Store 1.0. This affects an unknown part o...
CVE-2025-12336CRITICAL9.8A vulnerability was identified in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn...
CVE-2025-12325CRITICAL9.8A vulnerability has been found in SourceCodester Best Salon Management System 1.0. This affects an unknown part of the f...
CVE-2025-12316CRITICAL9.8A vulnerability was identified in code-projects Courier Management System 1.0. This impacts an unknown function of the f...
CVE-2025-12315CRITICAL9.8A vulnerability was determined in code-projects Food Ordering System 1.0. This affects an unknown function of the file /...
CVE-2025-12314CRITICAL9.8A vulnerability was found in code-projects Food Ordering System 1.0. The impacted element is an unknown function of the ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now