2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27034CRITICAL9.8Memory corruption while selecting the PLMN from SOR failed list.
CVE-2025-21483CRITICAL9.8Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs.
CVE-2025-9054CRITICAL9.8The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to unauthorized modi...
CVE-2025-41715CRITICAL9.8The database for the web application is exposed without authentication, allowing an unauthenticated remote attacker to g...
CVE-2025-59545CRITICAL9DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to v...
CVE-2025-4993CRITICAL9.1Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. Th...
CVE-2025-1255CRITICAL9.1Untrusted Pointer Dereference vulnerability in RTI Connext Professional (Core Libraries) allows Pointer Manipulation. Th...
CVE-2025-9846CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in TalentSys Consulting Information Technology Industry In...
CVE-2025-9965CRITICAL9.3Improper authentication vulnerability in Novakon P series allows unauthenticated attackers to upload and download any ap...
CVE-2025-9963CRITICAL9.4A path traversal vulnerability in Novakon P series allows to expose the root file system "/" and modify all files with r...
CVE-2025-9962CRITICAL10A buffer overflow vulnerability in Novakon P series allows attackers to gain root permission without prior authenticatio...
CVE-2025-10412CRITICAL9.8The Product Options and Price Calculation Formulas for WooCommerce – Uni CPO (Premium) plugin for WordPress is vulnerabl...
CVE-2025-10857CRITICAL9.8A security flaw has been discovered in Campcodes Point of Sale System POS 1.0. Affected by this issue is some unknown fu...
CVE-2025-10147CRITICAL9.8The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type vali...
CVE-2025-9588CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Iron Mountai...
CVE-2025-10851CRITICAL9.8A security flaw has been discovered in Campcodes Gym Management System 1.0. Impacted is an unknown function of the file ...
CVE-2025-10843CRITICAL9.8A flaw has been found in Reservation Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown f...
CVE-2025-10842CRITICAL9.8A vulnerability was detected in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /ad...
CVE-2025-10841CRITICAL9.8A security vulnerability has been detected in code-projects Online Bidding System 1.0. This impacts an unknown function ...
CVE-2025-9321CRITICAL9.8The WPCasa plugin for WordPress is vulnerable to Code Injection in all versions up to, and including, 1.4.1. This is due...
CVE-2025-26399CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code executi...
CVE-2025-10836CRITICAL9.8A weakness has been identified in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function o...
CVE-2025-10834CRITICAL9.8A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. This affects an unknown function of the file ...
CVE-2025-10833CRITICAL9.8A vulnerability was determined in 1000projects Bookstore Management System 1.0. The impacted element is an unknown funct...
CVE-2025-10832CRITICAL9.8A vulnerability was found in SourceCodester Pet Grooming Management Software 1.0. The affected element is an unknown fun...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now