2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-43982CRITICAL9.8Shenzhen Tuoshi NR500-EA RG500UEAABxCOMSLICv3.4.2731.16.43 devices enable the SSH service by default. There is a hidden ...
CVE-2025-8925CRITICAL9.8A vulnerability has been found in itsourcecode Sports Management System 1.0. Affected is an unknown function of the file...
CVE-2025-8924CRITICAL9.8A vulnerability was identified in Campcodes Online Water Billing System 1.0. This issue affects some unknown processing ...
CVE-2025-8923CRITICAL9.8A vulnerability was determined in code-projects Job Diary 1.0. This vulnerability affects unknown code of the file /edit...
CVE-2025-8922CRITICAL9.8A vulnerability was found in code-projects Job Diary 1.0. This affects an unknown part of the file /admin-inbox.php. The...
CVE-2025-8921CRITICAL9.8A vulnerability has been found in code-projects Job Diary 1.0. Affected by this issue is some unknown functionality of t...
CVE-2025-8904CRITICAL9Amazon EMR Secret Agent creates a keytab file containing Kerberos credentials. This file is stored in the /tmp/ director...
CVE-2025-23304CRITICAL9.8NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could c...
CVE-2025-23303CRITICAL9.8NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted...
CVE-2025-52385CRITICAL9.8An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to ...
CVE-2025-51451CRITICAL9.8In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginA...
CVE-2025-50594CRITICAL9.8An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health ...
CVE-2025-34153CRITICAL10Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code...
CVE-2025-51452CRITICAL9.8In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through fo...
CVE-2025-50251CRITICAL9.1Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
CVE-2025-54074CRITICAL9.8Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio ...
CVE-2025-8908CRITICAL9.8A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this ...
CVE-2025-8913CRITICAL9.8Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re...
CVE-2025-8760CRITICAL9.8A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co...
CVE-2025-6715CRITICAL9.8The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes...
CVE-2025-7384CRITICAL9.8The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ...
CVE-2025-55168CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio...
CVE-2025-25256CRITICAL9.8An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in ...
CVE-2025-53766CRITICAL9.8Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2025-50171CRITICAL9.1Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now