2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-2611CRITICAL9.3The ICTBroadcast application unsafely passes session cookie data to shell processing, allowing an attacker to inject she...
CVE-2025-54987CRITICAL9.8A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ...
CVE-2025-54948CRITICAL9.8A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker ...
CVE-2025-54982CRITICAL9.6An improper verification of cryptographic signature in Zscaler's SAML authentication mechanism on the server-side allowe...
CVE-2025-53417CRITICAL9.3DIAView (v4.2.0 and prior) - Directory Traversal Information Disclosure Vulnerability
CVE-2025-8535CRITICAL9A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects...
CVE-2025-54865CRITICAL9.8Tilesheets MediaWiki Extension adds a table lookup parser function for an item and returns the requested image. A missin...
CVE-2025-54802CRITICAL9.8pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there i...
CVE-2025-54795CRITICAL9.8Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass...
CVE-2025-54794CRITICAL9.1Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead o...
CVE-2025-54387CRITICAL9.8IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 throu...
CVE-2025-54135CRITICAL9.8Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in...
CVE-2025-54130CRITICAL9.8Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in...
CVE-2025-54119CRITICAL10ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versi...
CVE-2025-27212CRITICAL9.8An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a...
CVE-2025-8526CRITICAL9.8A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the ...
CVE-2025-51387CRITICAL9.8The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifical...
CVE-2025-50754CRITICAL9.6Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A mali...
CVE-2025-50341CRITICAL9.8A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can ma...
CVE-2025-52239CRITICAL9.8An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2025-51390CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter...
CVE-2025-34147CRITICAL9.4An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ...
CVE-2025-51535CRITICAL9.1Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
CVE-2025-44954CRITICAL9.8RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
CVE-2025-51536CRITICAL9.8Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now