2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-23303CRITICAL9.8NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted...
CVE-2025-52385CRITICAL9.8An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to ...
CVE-2025-51451CRITICAL9.8In TOTOLINK EX1200T firmware 4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginA...
CVE-2025-50594CRITICAL9.8An issue was discovered in /Code/Websites/DanpheEMR/Controllers/Settings/SecuritySettingsController.cs in Danphe Health ...
CVE-2025-34153CRITICAL10Hyland OnBase versions prior to 17.0.2.87 (other versions may be affected) are vulnerable to unauthenticated remote code...
CVE-2025-51452CRITICAL9.8In TOTOLINK A7000R firmware 9.1.0u.6115_B20201022, an attacker can bypass login by sending a specific request through fo...
CVE-2025-50251CRITICAL9.1Server side request forgery (SSRF) vulnerability in makeplane plane 0.23.1 via the password recovery.
CVE-2025-54074CRITICAL9.8Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.2.5 to 1.5.1, Cherry Studio ...
CVE-2025-8908CRITICAL9.8A vulnerability was determined in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.5.4. Affected by this ...
CVE-2025-8913CRITICAL9.8Organization Portal System developed by WellChoose has a Local File Inclusion vulnerability, allowing unauthenticated re...
CVE-2025-8760CRITICAL9.8A vulnerability was identified in INSTAR 2K+ and 4K 3.11.1 Build 1124. This affects the function base64_decode of the co...
CVE-2025-6715CRITICAL9.8The LatePoint WordPress plugin before 5.1.94 is vulnerable to Local File Inclusion via the layout parameter. This makes...
CVE-2025-7384CRITICAL9.8The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to PHP Object Injection in ...
CVE-2025-55168CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio...
CVE-2025-25256CRITICAL9.8An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vul...
CVE-2025-53766CRITICAL9.8Heap-based buffer overflow in Windows GDI+ allows an unauthorized attacker to execute code over a network.
CVE-2025-50171CRITICAL9.1Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
CVE-2025-50165CRITICAL9.8Untrusted pointer dereference in Microsoft Graphics Component allows an unauthorized attacker to execute code over a net...
CVE-2025-55167CRITICAL9.8WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to versio...
CVE-2025-24325CRITICAL9.3Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 ma...
CVE-2025-3831CRITICAL9.8Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
CVE-2025-8059CRITICAL9.8The B Blocks plugin for WordPress is vulnerable to Privilege Escalation due to missing authorization and improper input ...
CVE-2025-42957CRITICAL9.9SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T...
CVE-2025-42950CRITICAL9.9SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo...
CVE-2025-55161CRITICAL9.8Stirling-PDF is a locally hosted web application that performs various operations on PDF files. Prior to version 1.1.0, ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now