2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52122CRITICAL9.8Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability...
CVE-2025-50989CRITICAL9.1OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (...
CVE-2025-50972CRITICAL9.8SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via ...
CVE-2025-43728CRITICAL9.8Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated...
CVE-2025-9523CRITICAL9.8A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /gof...
CVE-2025-30063CRITICAL9.4The configuration file containing database logins and passwords is readable by any local user.
CVE-2025-30057CRITICAL9.4In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() ...
CVE-2025-30056CRITICAL9.4The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker ...
CVE-2025-30055CRITICAL9The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible...
CVE-2025-30041CRITICAL9The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/Clini...
CVE-2025-30040CRITICAL9The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "...
CVE-2025-30039CRITICAL9Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session ...
CVE-2025-2313CRITICAL9.4In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" par...
CVE-2025-9511CRITICAL9.8A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code ...
CVE-2025-9510CRITICAL9.8A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an u...
CVE-2025-9509CRITICAL9.8A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown pro...
CVE-2025-9508CRITICAL9.8A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown functio...
CVE-2025-9507CRITICAL9.8A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the f...
CVE-2025-9506CRITICAL9.8A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file ...
CVE-2025-9505CRITICAL9.8A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionali...
CVE-2025-9504CRITICAL9.8A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknow...
CVE-2025-9503CRITICAL9.8A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown functi...
CVE-2025-9502CRITICAL9.8A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the f...
CVE-2025-35115CRITICAL9.2Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Midd...
CVE-2025-22408CRITICAL9.8In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now