2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-53006CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, in both PostgreS...
CVE-2025-34073CRITICAL10An unauthenticated command injection vulnerability exists in stamparm/maltrail (Maltrail) versions <=0.54. A remote atta...
CVE-2025-34072CRITICAL9.3A data exfiltration vulnerability exists in Anthropic’s deprecated Slack Model Context Protocol (MCP) Server via automat...
CVE-2025-34071CRITICAL9.8A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload a...
CVE-2025-34070CRITICAL9.8A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remot...
CVE-2025-34069CRITICAL9.8An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and...
CVE-2025-34067CRITICAL10An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Se...
CVE-2025-5746CRITICAL9.8The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads ...
CVE-2025-4689CRITICAL9.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus...
CVE-2025-4380CRITICAL9.8The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to Local File Inclus...
CVE-2025-52101CRITICAL9.8linjiashop <=0.9 is vulnerable to Incorrect Access Control. When using the default-generated JWT authentication, attacke...
CVE-2025-45006CRITICAL9.1Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec co...
CVE-2025-53104CRITICAL9.1gluestack-ui is a library of copy-pasteable components & patterns crafted with Tailwind CSS (NativeWind). Prior to commi...
CVE-2025-37099CRITICAL9.8A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
CVE-2025-6963CRITICAL9.8A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerabilit...
CVE-2025-6962CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects a...
CVE-2025-6961CRITICAL9.8A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected ...
CVE-2025-6960CRITICAL9.8A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerabi...
CVE-2025-6959CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknow...
CVE-2025-6958CRITICAL9.8A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects...
CVE-2025-6957CRITICAL9.8A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerabil...
CVE-2025-34064CRITICAL9A cloud infrastructure misconfiguration in OneLogin AD Connector results in log data being sent to a hardcoded S3 bucket...
CVE-2025-34063CRITICAL10A cryptographic authentication bypass vulnerability exists in OneLogin AD Connector prior to 6.1.5 due to the exposure o...
CVE-2025-34060CRITICAL10A PHP objection injection vulnerability exists in the Monero Project’s Laravel-based forum software due to unsafe handli...
CVE-2025-34056CRITICAL9.4An OS command injection vulnerability exists in AVTECH IP camera, DVR, and NVR devices via the PwdGrp.cgi endpoint, whic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now