2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52122 | CRITICAL | 9.8 | 0.6% | Aug 27, 2025 | Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability... |
| CVE-2025-50989 | CRITICAL | 9.1 | 8.0% | Aug 27, 2025 | OPNsense before 25.1.8 contains an authenticated command injection vulnerability in its Bridge Interface Edit endpoint (... |
| CVE-2025-50972 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | SQL Injection vulnerability in AbanteCart 1.4.2, allows unauthenticated attackers to execute arbitrary SQL commands via ... |
| CVE-2025-43728 | CRITICAL | 9.8 | 0.3% | Aug 27, 2025 | Dell ThinOS 10, versions prior to 2508_10.0127, contain a Protection Mechanism Failure vulnerability. An unauthenticated... |
| CVE-2025-9523 | CRITICAL | 9.8 | 1.0% | Aug 27, 2025 | A vulnerability was detected in Tenda AC1206 15.03.06.23. Affected is the function GetParentControlInfo of the file /gof... |
| CVE-2025-30063 | CRITICAL | 9.4 | 0.1% | Aug 27, 2025 | The configuration file containing database logins and passwords is readable by any local user. |
| CVE-2025-30057 | CRITICAL | 9.4 | 0.7% | Aug 27, 2025 | In UHCRTFDoc, the filename parameter can be exploited to execute arbitrary code via command injection into the system() ... |
| CVE-2025-30056 | CRITICAL | 9.4 | 0.2% | Aug 27, 2025 | The RunCommand function accepts any parameter, which is then passed for execution in the shell. This allows an attacker ... |
| CVE-2025-30055 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The "system" function receives untrusted input from the user. If the "EnableJSCaching" option is enabled, it is possible... |
| CVE-2025-30041 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The paths "/cgi-bin/CliniNET.prd/utils/userlogstat.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", and "/cgi-bin/Clini... |
| CVE-2025-30040 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | The vulnerability allows unauthenticated users to download a file containing session ID data by directly accessing the "... |
| CVE-2025-30039 | CRITICAL | 9 | 0.2% | Aug 27, 2025 | Unauthenticated access to the "/cgi-bin/CliniNET.prd/GetActiveSessions.pl" endpoint allows takeover of any user session ... |
| CVE-2025-2313 | CRITICAL | 9.4 | 0.2% | Aug 27, 2025 | In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" par... |
| CVE-2025-9511 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A vulnerability was identified in itsourcecode Apartment Management System 1.0. This vulnerability affects unknown code ... |
| CVE-2025-9510 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A security vulnerability has been detected in itsourcecode Apartment Management System 1.0. The affected element is an u... |
| CVE-2025-9509 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A security flaw has been discovered in itsourcecode Apartment Management System 1.0. This issue affects some unknown pro... |
| CVE-2025-9508 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A vulnerability was detected in itsourcecode Apartment Management System 1.0. The impacted element is an unknown functio... |
| CVE-2025-9507 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A weakness has been identified in itsourcecode Apartment Management System 1.0. Impacted is an unknown function of the f... |
| CVE-2025-9506 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A vulnerability has been found in Campcodes Online Loan Management System 1.0. This affects an unknown part of the file ... |
| CVE-2025-9505 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A flaw has been found in Campcodes Online Loan Management System 1.0. Affected by this issue is some unknown functionali... |
| CVE-2025-9504 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A vulnerability was detected in Campcodes Online Loan Management System 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-9503 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A security vulnerability has been detected in Campcodes Online Loan Management System 1.0. Affected is an unknown functi... |
| CVE-2025-9502 | CRITICAL | 9.8 | 0.4% | Aug 27, 2025 | A weakness has been identified in Campcodes Online Loan Management System 1.0. This impacts an unknown function of the f... |
| CVE-2025-35115 | CRITICAL | 9.2 | 0.2% | Aug 26, 2025 | Agiloft Release 28 downloads critical system packages over an insecure HTTP connection. An attacker in a Man-In-the-Midd... |
| CVE-2025-22408 | CRITICAL | 9.8 | 0.4% | Aug 26, 2025 | In rfc_check_send_cmd of rfc_utils.cc, there is a possible way to execute arbitrary code due to a use after free. This c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now