2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52395CRITICAL9.8An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password ...
CVE-2025-9305CRITICAL9.8A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is ...
CVE-2025-9304CRITICAL9.8A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of t...
CVE-2025-9303CRITICAL9.8A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParental...
CVE-2025-53251CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in An-Themes Pin WP pin-wp allows Upload a Web Shell to a ...
CVE-2025-9302CRITICAL9.8A vulnerability was identified in PHPGurukul User Management System 1.0. This vulnerability affects unknown code of the ...
CVE-2025-9299CRITICAL9.8A vulnerability has been found in Tenda M3 1.0.0.12. Affected by this vulnerability is the function formGetMasterPasseng...
CVE-2025-9298CRITICAL9.8A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Exec...
CVE-2025-9296CRITICAL9.8A security vulnerability has been detected in Emlog Pro up to 2.5.18. This affects an unknown function of the file /admi...
CVE-2025-8895CRITICAL9.8The WP Webhooks plugin for WordPress is vulnerable to arbitrary file copy due to missing validation of user-supplied inp...
CVE-2025-7390CRITICAL9.1A malicious client can bypass the client certificate trust check of an opc.https server when the server endpoint is conf...
CVE-2025-43300CRITICAL10An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.8.5 and iPadOS 1...
CVE-2025-27217CRITICAL9.1A Server-Side Request Forgery (SSRF) in the UISP Application may allow a malicious actor with certain permissions to mak...
CVE-2025-27214CRITICAL9.8A Missing Authentication for Critical Function vulnerability in the UniFi Connect EV Station Pro may allow a malicious a...
CVE-2025-24285CRITICAL9.8Multiple Improper Input Validation vulnerabilities in UniFi Connect EV Station Lite may allow a Command Injection by a m...
CVE-2025-9288CRITICAL9.1Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4....
CVE-2025-9287CRITICAL9.1Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: th...
CVE-2025-8611CRITICAL9.8AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-8610CRITICAL9.8AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-55444CRITICAL9.8A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts...
CVE-2025-50904CRITICAL9.8There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can...
CVE-2025-50901CRITICAL9.8JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, whi...
CVE-2025-9074CRITICAL9.3A vulnerability was identified in Docker Desktop that allows local running Linux containers to access the Docker Engine ...
CVE-2025-32010CRITICAL9.8A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A spe...
CVE-2025-31355CRITICAL9.8A firmware update vulnerability exists in the Firmware Signature Validation functionality of Tenda AC6 V5.0 V02.03.01.11...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now