2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10251CRITICAL9.8A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/adm...
CVE-2025-40692CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40691CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40690CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40689CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-40687CRITICAL9.8SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre...
CVE-2025-58321CRITICAL10Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability.
CVE-2025-8570CRITICAL9.8The BeyondCart Connector plugin for WordPress is vulnerable to Privilege Escalation due to improper JWT secret managemen...
CVE-2025-10218CRITICAL9.8A flaw has been found in lostvip-com ruoyi-go 2.1. This affects the function SelectListPage of the file modules/system/d...
CVE-2025-54123CRITICAL9.8Hoverfly is an open source API simulation tool. In versions 1.11.3 and prior, the middleware functionality in Hoverfly i...
CVE-2025-59041CRITICAL9.8Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.ema...
CVE-2025-58764CRITICAL9.8Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to ...
CVE-2025-10226CRITICAL9.8Dependency on Vulnerable Third-Party Component (CWE-1395) in the PostgreSQL backend in AxxonSoft Axxon One (C-Werk) 2.0....
CVE-2025-10220CRITICAL9.8Use of Unmaintained Third Party Components (CWE-1104) in the NuGet dependency components in AxxonSoft Axxon One VMS 2.0....
CVE-2025-9943CRITICAL9.1An SQL injection vulnerability has been identified in the "ID" attribute of the SAML response when the replay cache of t...
CVE-2025-59046CRITICAL9.8The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc...
CVE-2025-59039CRITICAL9.3Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest we...
CVE-2025-58750CRITICAL9.1rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58448CRITICAL9.8rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58447CRITICAL9.8rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58768CRITICAL9.6DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo...
CVE-2025-58462CRITICAL9.8OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r...
CVE-2025-57633CRITICAL9.8A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute...
CVE-2025-43491CRITICAL9.8A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi...
CVE-2025-23344CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now