2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34522 | CRITICAL | 9.8 | 0.5% | Aug 27, 2025 | A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). ... |
| CVE-2025-34520 | CRITICAL | 9.8 | 0.3% | Aug 27, 2025 | An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai... |
| CVE-2025-34163 | CRITICAL | 10 | 0.7% | Aug 27, 2025 | Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce ... |
| CVE-2025-34162 | CRITICAL | 9.3 | 0.8% | Aug 27, 2025 | An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Eme... |
| CVE-2025-34160 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port... |
| CVE-2025-58050 | CRITICAL | 9.1 | 0.7% | Aug 27, 2025 | The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b... |
| CVE-2025-50428 | CRITICAL | 9.8 | 1.6% | Aug 27, 2025 | In RaspAP raspap-webgui 3.3.2 and earlier, a command injection vulnerability exists in the includes/hostapd.php script. ... |
| CVE-2025-34157 | CRITICAL | 9 | 0.4% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a stored cross-site scripting (XSS) attack in the project ... |
| CVE-2025-9533 | CRITICAL | 9.8 | 9.2% | Aug 27, 2025 | A vulnerability has been found in TOTOLINK T10 4.1.8cu.5241_B20210927. Affected is an unknown function of the file /form... |
| CVE-2025-52122 | CRITICAL | 9.8 | 0.6% | Aug 27, 2025 | Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability... |
| CVE-2025-50989 | CRITICAL | 9.1 | 8.0% | Aug 27, 2025 | OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (... |
| CVE-2025-50972 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via ... |
| CVE-2025-43728 | CRITICAL | 9.8 | 0.3% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated... |
| CVE-2025-9523 | CRITICAL | 9.8 | 1.0% | Aug 27, 2025 | A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /gof... |
| CVE-2025-30063 | CRITICAL | 9.4 | 0.1% | Aug 27, 2025 | The configuration file containing database logins and passwords is readable by any local user. |
| CVE-2025-30057 | CRITICAL | 9.4 | 0.7% | Aug 27, 2025 | In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() ... |
| CVE-2025-30056 | CRITICAL | 9.4 | 0.2% | Aug 27, 2025 | The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker ... |
| CVE-2025-30055 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible... |
| CVE-2025-30041 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/Clini... |
| CVE-2025-30040 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "... |
| CVE-2025-30039 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session ... |
| CVE-2025-2313 | CRITICAL | 9.4 | 0.2% | Aug 27, 2025 | In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" par... |
| CVE-2025-9511 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code ... |
| CVE-2025-9510 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an u... |
| CVE-2025-9509 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown pro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now