2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-59827CRITICAL9.8Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper acc...
CVE-2025-59828CRITICAL9.8Claude Code is an agentic coding tool. Prior to Claude Code version 1.0.39, when using Claude Code with Yarn versions 2....
CVE-2025-57321CRITICAL9.8A Prototype Pollution vulnerability in the util-deps.addFileDepend function of magix-combine-ex versions thru 1.2.10 all...
CVE-2025-57347CRITICAL9.8A vulnerability exists in the 'dagre-d3-es' Node.js package version 7.0.9, specifically within the 'bk' module's addConf...
CVE-2025-52906CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TOTOLINK X60...
CVE-2025-10890CRITICAL9.1Side-channel information leakage in V8 in Google Chrome prior to 140.0.7339.207 allowed a remote attacker to leak cross-...
CVE-2025-10585CRITICAL9.8Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corr...
CVE-2025-56819CRITICAL9.8An issue in Datart v.1.0.0-rc.3 allows a remote attacker to execute arbitrary code via the INIT connection parameter.
CVE-2025-27034CRITICAL9.8Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-21483CRITICAL9.8Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-9054CRITICAL9.8The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi...
CVE-2025-41715CRITICAL9.8The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g...
CVE-2025-59545CRITICAL9DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-4993CRITICAL9.1Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi...
CVE-2025-1255CRITICAL9.1Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation.Thi...
CVE-2025-9846CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry In...
CVE-2025-9965CRITICAL9.3Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any ap...
CVE-2025-9963CRITICAL9.4A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with r...
CVE-2025-9962CRITICAL10A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authenticatio...
CVE-2025-10412CRITICAL9.8The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl...
CVE-2025-10857CRITICAL9.8A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown fu...
CVE-2025-10147CRITICAL9.8The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2025-9588CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountai...
CVE-2025-10851CRITICAL9.8A security flaw has been discovered in Campcodes Gym Management System 1.0. Impacted is an unknown function of the file ...
CVE-2025-10843CRITICAL9.8A flaw has been found in Reservation Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown f...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now