2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-34522CRITICAL9.8A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). ...
CVE-2025-34520CRITICAL9.8An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai...
CVE-2025-34163CRITICAL10Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce ...
CVE-2025-34162CRITICAL9.3An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Eme...
CVE-2025-34160CRITICAL10AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port...
CVE-2025-58050CRITICAL9.1The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b...
CVE-2025-50428CRITICAL9.8In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. ...
CVE-2025-34157CRITICAL9Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project ...
CVE-2025-9533CRITICAL9.8A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form...
CVE-2025-52122CRITICAL9.8Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability...
CVE-2025-50989CRITICAL9.1OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (...
CVE-2025-50972CRITICAL9.8SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via ...
CVE-2025-43728CRITICAL9.8Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated...
CVE-2025-9523CRITICAL9.8A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /gof...
CVE-2025-30063CRITICAL9.4The configuration file containing database logins and passwords is readable by any local user.
CVE-2025-30057CRITICAL9.4In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() ...
CVE-2025-30056CRITICAL9.4The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker ...
CVE-2025-30055CRITICAL9The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible...
CVE-2025-30041CRITICAL9The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/Clini...
CVE-2025-30040CRITICAL9The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "...
CVE-2025-30039CRITICAL9Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session ...
CVE-2025-2313CRITICAL9.4In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" par...
CVE-2025-9511CRITICAL9.8A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code ...
CVE-2025-9510CRITICAL9.8A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an u...
CVE-2025-9509CRITICAL9.8A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown pro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now