2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-9113CRITICAL9.8The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2025-10103CRITICAL9.8A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the...
CVE-2025-10102CRITICAL9.8A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o...
CVE-2025-57285CRITICAL9.8codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com...
CVE-2025-56267CRITICAL9.8A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitr...
CVE-2025-56266CRITICAL9.8A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin...
CVE-2025-10100CRITICAL9.8A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t...
CVE-2025-10097CRITICAL9.8A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app...
CVE-2025-57141CRITICAL9.8rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
CVE-2025-52161CRITICAL9.8Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vu...
CVE-2025-22956CRITICAL9.8OPSI before 4.3 allows any client to retrieve any ProductPropertyState, including those of other clients. This can lead ...
CVE-2025-10092CRITICAL9.8A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectman...
CVE-2025-5993CRITICAL9.2ITCube CRM in versions from 2023.2 through 2025.2 is vulnerable to path traversal. Unauthenticated remote attacker is ab...
CVE-2025-10091CRITICAL9.8A vulnerability has been found in Jinher OA up to 1.2. This affects an unknown function of the file /c6/Jhsoft.Web.proje...
CVE-2025-10090CRITICAL9.8A flaw has been found in Jinher OA up to 1.2. The impacted element is an unknown function of the file /C6/Jhsoft.Web.dep...
CVE-2025-10082CRITICAL9.8A vulnerability has been found in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file ...
CVE-2025-10079CRITICAL9.8A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the fil...
CVE-2025-10078CRITICAL9.8A vulnerability was detected in SourceCodester Online Polling System 1.0. Affected is an unknown function of the file /a...
CVE-2025-10077CRITICAL9.8A security vulnerability has been detected in SourceCodester Online Polling System 1.0. This impacts an unknown function...
CVE-2025-10076CRITICAL9.8A weakness has been identified in SourceCodester Online Polling System 1.0. This affects an unknown function of the file...
CVE-2025-10068CRITICAL9.8A flaw has been found in itsourcecode Online Discussion Forum 1.0. This affects an unknown function of the file /admin/a...
CVE-2025-10062CRITICAL9.8A vulnerability was determined in itsourcecode Student Information Management System 1.0. This affects an unknown part o...
CVE-2025-58443CRITICAL9.1FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Versions 1.5.10.1673 and below conta...
CVE-2025-58438CRITICAL9.4internetarchive is a Python and Command-Line Interface to Archive.org In versions 5.5.0 and below, there is a directory ...
CVE-2025-10034CRITICAL9.8A vulnerability was found in D-Link DIR-825 1.08.01. This impacts the function get_ping6_app_stat of the file ping6_resp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now