2025 CVE Vulnerabilities

45,139 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-29365CRITICAL9.8spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.
CVE-2025-9254CRITICAL9.8WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log ...
CVE-2025-53795CRITICAL9.8Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-53763CRITICAL9.8Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-3128CRITICAL9.8A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamp...
CVE-2025-52352CRITICAL9.8Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed d...
CVE-2025-9311CRITICAL9.8A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown f...
CVE-2025-57754CRITICAL9.8eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is ex...
CVE-2025-9307CRITICAL9.8A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/...
CVE-2025-52395CRITICAL9.8An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password ...
CVE-2025-9305CRITICAL9.8A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is ...
CVE-2025-9304CRITICAL9.8A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of t...
CVE-2025-9303CRITICAL9.8A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParental...
CVE-2025-53251CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a ...
CVE-2025-9302CRITICAL9.8A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the ...
CVE-2025-9299CRITICAL9.8A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPasseng...
CVE-2025-9298CRITICAL9.8A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Exec...
CVE-2025-9296CRITICAL9.8A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admi...
CVE-2025-8895CRITICAL9.8The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied inp...
CVE-2025-7390CRITICAL9.1A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is conf...
CVE-2025-43300CRITICAL10An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1...
CVE-2025-27217CRITICAL9.1A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to mak...
CVE-2025-27214CRITICAL9.8A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious a...
CVE-2025-24285CRITICAL9.8Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a m...
CVE-2025-9288CRITICAL9.1Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now