2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-4383CRITICAL9.3Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm....
CVE-2025-6567CRITICAL9.8A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This iss...
CVE-2025-32977CRITICAL9.6Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-32975CRITICAL10Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14....
CVE-2025-6433CRITICAL9.8If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a...
CVE-2025-6427CRITICAL9.1An attacker was able to bypass the `connect-src` directive of a Content Security Policy by manipulating subdocuments. Th...
CVE-2025-6424CRITICAL9.8A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability was fixed in Firefox 140...
CVE-2025-50213CRITICAL9.8Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) vulnerability in Apache Airflow ...
CVE-2025-48890CRITICAL9.8WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje...
CVE-2025-43879CRITICAL9.8WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Inje...
CVE-2025-6560CRITICAL9.8Multiple wireless router models from Sapido have an Exposure of Sensitive Information vulnerability, allowing unauthenti...
CVE-2025-6559CRITICAL9.8Multiple wireless router models from Sapido have an OS Command Injection vulnerability, allowing unauthenticated remote ...
CVE-2025-48469CRITICAL9.6Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload firmware through a public...
CVE-2025-34041CRITICAL10An OS command injection vulnerability exists in the Chinese versions of Sangfor Endpoint Detection and Response (EDR) ma...
CVE-2025-34040CRITICAL10An arbitrary file upload vulnerability exists in the Zhiyuan OA platform via the wpsAssistServlet interface. The realFil...
CVE-2025-34039CRITICAL10A code injection vulnerability exists in Yonyou UFIDA NC v6.5 and prior due to the exposure of the BeanShell testing ser...
CVE-2025-34037CRITICAL10An OS command injection vulnerability exists in various models of E-Series Linksys routers via the /tmUnblock.cgi and /h...
CVE-2025-34036CRITICAL9.8An OS command injection vulnerability exists in white-labeled DVRs manufactured by TVT, affecting a custom HTTP service ...
CVE-2025-34035CRITICAL9.8An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbintera...
CVE-2025-52562CRITICAL10Convoy is a KVM server management panel for hosting businesses. In versions 3.9.0-rc3 to before 4.4.1, there is a direct...
CVE-2025-2828CRITICAL10A Server-Side Request Forgery (SSRF) vulnerability exists in the RequestsToolkit component of the langchain-community pa...
CVE-2025-6547CRITICAL9.1Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation.This issue affects pb...
CVE-2025-6545CRITICAL9.1Improper Input Validation vulnerability in pbkdf2 allows Signature Spoofing by Improper Validation. This vulnerability i...
CVE-2025-6517CRITICAL9.8A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add ...
CVE-2025-46101CRITICAL9.8SQL Injection vulnerability in Beakon Software Beakon Learning Management System Sharable Content Object Reference Model...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now