2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-6580CRITICAL9.8A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an...
CVE-2025-52572CRITICAL10Hikka, a Telegram userbot, has vulnerability affects all users on all versions of Hikka. Two scenarios are possible. 1. ...
CVE-2025-6579CRITICAL9.8A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some...
CVE-2025-6578CRITICAL9.8A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical....
CVE-2025-52571CRITICAL9.6Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It ...
CVE-2025-52471CRITICAL9.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. An integer underflow vulnerability has been ide...
CVE-2025-49853CRITICAL9.3ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacke...
CVE-2025-49851CRITICAL9.8ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability wh...
CVE-2025-2566CRITICAL9.3Kaleris NAVIS N4 ULC (Ultra Light Client) contains an unsafe Java deserialization vulnerability. An unauthenticated atta...
CVE-2025-4378CRITICAL10Cleartext Transmission of Sensitive Information, Use of Hard-coded Credentials vulnerability in Ataturk University ATA-A...
CVE-2025-4383CRITICAL9.3Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm....
CVE-2025-6567CRITICAL9.8A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This iss...
CVE-2025-32977CRITICAL9.6Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-32975CRITICAL10Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-6433CRITICAL9.8If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a...
CVE-2025-6427CRITICAL9.1An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th...
CVE-2025-6424CRITICAL9.8A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140...
CVE-2025-50213CRITICAL9.8Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow ...
CVE-2025-48890CRITICAL9.8WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje...
CVE-2025-43879CRITICAL9.8WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje...
CVE-2025-6560CRITICAL9.8Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenti...
CVE-2025-6559CRITICAL9.8Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote ...
CVE-2025-48469CRITICAL9.6Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public...
CVE-2025-34041CRITICAL10An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) ma...
CVE-2025-34040CRITICAL10An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now