2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10662CRITICAL9.8A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_memb...
CVE-2025-6237CRITICAL9.8A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file del...
CVE-2025-9083CRITICAL9.8The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticate...
CVE-2025-8942CRITICAL9.1The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an a...
CVE-2025-5305CRITICAL9.8The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound ...
CVE-2025-10624CRITICAL9.8A security flaw has been discovered in PHPGurukul User Management System 1.0. This affects an unknown function of the fi...
CVE-2025-10623CRITICAL9.8A vulnerability was identified in SourceCodester Hotel Reservation System 1.0. The impacted element is an unknown functi...
CVE-2025-23316CRITICAL9.8NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker c...
CVE-2025-23268CRITICAL9.8NVIDIA Triton Inference Server contains a vulnerability in the DALI backend where an attacker may cause an improper inpu...
CVE-2025-10621CRITICAL9.8A vulnerability was determined in SourceCodester Hotel Reservation System 1.0. The affected element is an unknown functi...
CVE-2025-10644CRITICAL9.4Wondershare Repairit SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability a...
CVE-2025-10643CRITICAL9.1Wondershare Repairit Incorrect Permission Assignment Authentication Bypass Vulnerability. This vulnerability allows remo...
CVE-2025-59352CRITICAL9.8Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the gRPC API and ...
CVE-2025-59340CRITICAL10jinjava is a Java-based template engine based on django template syntax, adapted to render jinja templates. Priori to 2....
CVE-2025-59345CRITICAL9.1Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /api/v1/jobs ...
CVE-2025-58766CRITICAL9Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and ear...
CVE-2025-10604CRITICAL9.8A vulnerability was identified in PHPGurukul Online Discussion Forum 1.0. This affects an unknown part of the file /admi...
CVE-2025-59304CRITICAL9.8A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote...
CVE-2025-35434CRITICAL9.8CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces...
CVE-2025-10603CRITICAL9.8A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functio...
CVE-2025-10601CRITICAL9.8A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the...
CVE-2025-10600CRITICAL9.8A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r...
CVE-2025-10599CRITICAL9.8A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the...
CVE-2025-10598CRITICAL9.8A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown p...
CVE-2025-10597CRITICAL9.8A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vuln...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now