2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-54802CRITICAL9.8pyLoad is the free and open-source Download Manager written in pure Python. In versions 0.5.0b3.dev89 and below, there i...
CVE-2025-54795CRITICAL9.8Claude Code is an agentic coding tool. In versions below 1.0.20, an error in command parsing makes it possible to bypass...
CVE-2025-54794CRITICAL9.1Claude Code is an agentic coding tool. In versions below 0.2.111, a path validation flaw using prefix matching instead o...
CVE-2025-54387CRITICAL9.8IPX is an image optimizer powered by sharp and svgo. In versions 1.3.1 and below, 2.0.0-0 through 2.1.0, and 3.0.0 throu...
CVE-2025-54135CRITICAL9.8Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in...
CVE-2025-54130CRITICAL9.8Cursor is a code editor built for programming with AI. Cursor allows writing in-workspace files with no user approval in...
CVE-2025-54119CRITICAL10ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. In versi...
CVE-2025-27212CRITICAL9.8An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with a...
CVE-2025-8526CRITICAL9.8A vulnerability was found in Exrick xboot up to 3.3.4. It has been declared as critical. This vulnerability affects the ...
CVE-2025-51387CRITICAL9.8The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifical...
CVE-2025-50754CRITICAL9.6Unisite CMS version 5.0 contains a stored Cross-Site Scripting (XSS) vulnerability in the "Report" functionality. A mali...
CVE-2025-50341CRITICAL9.8A Boolean-based SQL injection vulnerability was discovered in Axelor 5.2.4 via the _domain parameter. An attacker can ma...
CVE-2025-52239CRITICAL9.8An arbitrary file upload vulnerability in ZKEACMS v4.1 allows attackers to execute arbitrary code via a crafted file.
CVE-2025-51390CRITICAL9.8TOTOLINK N600R V4.3.0cu.7647_B20210106 was discovered to contain a command injection vulnerability via the pin parameter...
CVE-2025-34147CRITICAL9.4An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ...
CVE-2025-51535CRITICAL9.1Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a SQL injection vulnerability.
CVE-2025-44954CRITICAL9.8RUCKUS SmartZone (SZ) before 6.1.2p3 Refresh Build has a hardcoded SSH private key for a root-equivalent user account.
CVE-2025-51536CRITICAL9.8Austrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.
CVE-2025-36594CRITICAL9.8Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3....
CVE-2025-36604CRITICAL9.8Dell Unity, version(s) 5.5 and prior, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('...
CVE-2025-6205CRITICAL9.1A missing authorization vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an atta...
CVE-2025-8504CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects Kitchen Treasure 1.0. This affects an unkn...
CVE-2025-8503CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Medicine Guide 1.0. Affected b...
CVE-2025-8502CRITICAL9.8A vulnerability classified as critical was found in code-projects Online Medicine Guide 1.0. Affected by this vulnerabil...
CVE-2025-8499CRITICAL9.8A vulnerability was found in code-projects Online Medicine Guide 1.0. It has been declared as critical. This vulnerabili...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now