2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-34082CRITICAL9.3A command injection vulnerability exists in IGEL OS versions prior to 11.04.270 within the Secure Terminal and Secure Sh...
CVE-2025-34061CRITICAL9.3A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code ...
CVE-2025-23968CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in WebFactory AiBud WP aibuddy-openai-chatgpt allows Uploa...
CVE-2025-27456CRITICAL9.8The SMB server's login mechanism does not implement sufficient measures to prevent multiple failed authentication attemp...
CVE-2025-27449CRITICAL9.8The MEAC300-FNADE4 does not implement sufficient measures to prevent multiple failed authentication attempts within a sh...
CVE-2025-1710CRITICAL9.8The maxView Storage Manager does not implement sufficient measures to prevent multiple failed authentication attempts wi...
CVE-2025-34074CRITICAL9.4An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design i...
CVE-2025-45813CRITICAL9.8ENENSYS IPGuard v2 2.10.0 was discovered to contain hardcoded credentials.
CVE-2025-45814CRITICAL9.8Missing authentication checks in the query.fcgi endpoint of NS3000 v8.1.1.125110 , v7.2.8.124852 , and v7.x and NS2000 v...
CVE-2025-20309CRITICAL10A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Ma...
CVE-2025-53006CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreS...
CVE-2025-34073CRITICAL10An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta...
CVE-2025-34072CRITICAL9.3A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat...
CVE-2025-34071CRITICAL9.8A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a...
CVE-2025-34070CRITICAL9.8A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot...
CVE-2025-34069CRITICAL9.8An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and...
CVE-2025-34067CRITICAL10An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Se...
CVE-2025-5746CRITICAL9.8The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ...
CVE-2025-4689CRITICAL9.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus...
CVE-2025-4380CRITICAL9.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus...
CVE-2025-52101CRITICAL9.8linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attacke...
CVE-2025-45006CRITICAL9.1Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec co...
CVE-2025-53104CRITICAL9.1gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi...
CVE-2025-37099CRITICAL9.8A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-6963CRITICAL9.8A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now