2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-5358CRITICAL9.8A vulnerability was found in PHPGurukul/Campcodes Cyber Cafe Management System 1.0. It has been rated as critical. Affec...
CVE-2025-5357CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been declared as critical. Affected by this vulnerability ...
CVE-2025-5356CRITICAL9.8A vulnerability was found in FreeFloat FTP Server 1.0. It has been classified as critical. Affected is an unknown functi...
CVE-2025-2500CRITICAL9.1A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an...
CVE-2025-48865CRITICAL9.1Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. Prior to version 1.6.6, Fabio allows cl...
CVE-2025-48481CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.180, an attacker with an unactivated ...
CVE-2025-47952CRITICAL9.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a...
CVE-2025-48757CRITICAL9.3An insufficient database Row-Level Security policy in Lovable through 2025-04-15 allows remote unauthenticated attackers...
CVE-2025-44619CRITICAL9.1Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attacker...
CVE-2025-46352CRITICAL9.8The CS5000 Fire Panel is vulnerable due to a hard-coded password that runs on a VNC server and is visible as a string i...
CVE-2025-41438CRITICAL9.8The CS5000 Fire Panel is vulnerable due to a default account that exists on the panel. Even though it is possible to ch...
CVE-2025-1907CRITICAL9.8Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if co...
CVE-2025-5332CRITICAL9.8A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some u...
CVE-2025-5331CRITICAL9.8A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown ...
CVE-2025-5330CRITICAL9.8A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o...
CVE-2025-31263CRITICAL9.1The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to ...
CVE-2025-30466CRITICAL9.8This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4...
CVE-2025-5325CRITICAL9.8A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified ...
CVE-2025-4967CRITICAL9.1Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
CVE-2025-48336CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This ...
CVE-2025-48471CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check o...
CVE-2025-5321CRITICAL9.9A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function R...
CVE-2025-48748CRITICAL10Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
CVE-2025-48047CRITICAL9.4An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via ...
CVE-2025-27151CRITICAL9.8Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now