2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10025CRITICAL9.8A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file...
CVE-2025-39682CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_...
CVE-2025-35452CRITICAL9.8PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use default, shared credentials for the administrative ...
CVE-2025-35451CRITICAL9.8PTZOptics and possibly other ValueHD-based pan-tilt-zoom cameras use hard-coded, default administrative credentials. The...
CVE-2025-58628CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav Mirac...
CVE-2025-58206CRITICAL9.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-49401CRITICAL9.8Incorrect Privilege Assignment vulnerability in axiomthemes smart SEO smartSEO allows Privilege Escalation.This issue af...
CVE-2025-58819CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow...
CVE-2025-55037CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in TkEasyGUI ver...
CVE-2025-55244CRITICAL9Azure Bot Service Elevation of Privilege Vulnerability
CVE-2025-55241CRITICAL10Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55190CRITICAL9.9Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. In versions 2.13.0 through 2.13.8, 2.14.0 thro...
CVE-2025-54914CRITICAL9.8Azure Networking Elevation of Privilege Vulnerability
CVE-2025-58361CRITICAL9.3Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version...
CVE-2025-8311CRITICAL9.4dotCMS versions 24.03.22 and after, identified a Boolean-based blind SQLi vulnerability in the /api/v1/contenttype endpo...
CVE-2025-7385CRITICAL9.3Input from search query parameter in GOV CMS is not sanitized properly, leading to a Blind SQL injection vulnerability, ...
CVE-2025-41034CRITICAL9.8An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c...
CVE-2025-41033CRITICAL9.8An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c...
CVE-2025-41032CRITICAL9.8An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c...
CVE-2025-9935CRITICAL9.8A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_415...
CVE-2025-9934CRITICAL9.8A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /c...
CVE-2025-9933CRITICAL9.8A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow...
CVE-2025-9932CRITICAL9.8A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown f...
CVE-2025-9930CRITICAL9.8A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown...
CVE-2025-58357CRITICAL9.65ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Version 0.13.2 con...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now