2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-30410CRITICAL9.8Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C...
CVE-2025-67305CRITICAL9.8In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These ...
CVE-2025-67304CRITICAL9.8In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL ...
CVE-2025-71243CRITICAL9.8The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex...
CVE-2025-55853CRITICAL9.1SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not...
CVE-2025-9953CRITICAL9.8Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd....
CVE-2025-8350CRITICAL9.8Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern...
CVE-2025-15559CRITICAL9.8An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server...
CVE-2025-15586CRITICAL10OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic...
CVE-2025-13851CRITICAL9.8The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re...
CVE-2025-13563CRITICAL9.8The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3...
CVE-2025-12882CRITICAL9.8The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ...
CVE-2025-70152CRITICAL9.8code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management...
CVE-2025-70150CRITICAL9.8CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al...
CVE-2025-14009CRITICAL10A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f...
CVE-2025-70149CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame...
CVE-2025-70146CRITICAL9.1Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera...
CVE-2025-70141CRITICAL9.4SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp...
CVE-2025-70998CRITICAL9.8UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel...
CVE-2025-65791CRITICAL9.8ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i...
CVE-2025-15579CRITICAL9.5Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection.  The vulnerabi...
CVE-2025-33089CRITICAL9.8IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac...
CVE-2025-66614CRITICAL9.1Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-...
CVE-2025-59793CRITICAL9.9Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica...
CVE-2025-70830CRITICAL9.9A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now