2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1907CRITICAL9.8Instantel Micromate lacks authentication on a configuration port which could allow an attacker to execute commands if co...
CVE-2025-5332CRITICAL9.8A vulnerability was found in 1000 Projects Online Notice Board 1.0 and classified as critical. This issue affects some u...
CVE-2025-5331CRITICAL9.8A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown ...
CVE-2025-5330CRITICAL9.8A vulnerability, which was classified as critical, was found in FreeFloat FTP Server 1.0. This affects an unknown part o...
CVE-2025-31263CRITICAL9.1The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.4. An app may be able to ...
CVE-2025-30466CRITICAL9.8This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4...
CVE-2025-5325CRITICAL9.8A vulnerability has been found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0 and classified ...
CVE-2025-4967CRITICAL9.1Esri Portal for ArcGIS 11.4 and prior allows a remote, unauthenticated attacker to bypass the Portal’s SSRF protections.
CVE-2025-48336CRITICAL9.8Deserialization of Untrusted Data vulnerability in ThimPress Course Builder course-builder allows Object Injection.This ...
CVE-2025-48471CRITICAL9.8FreeScout is a free self-hosted help desk and shared mailbox. Prior to version 1.8.179, the application does not check o...
CVE-2025-5321CRITICAL9.9A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function R...
CVE-2025-48748CRITICAL10Netwrix Directory Manager (formerly Imanami GroupID) through v.10.0.7784.0 has a hard-coded password.
CVE-2025-48047CRITICAL9.4An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via ...
CVE-2025-27151CRITICAL9.8Redis is an open source, in-memory database that persists on disk. In versions starting from 7.0.0 to before 8.0.2, a st...
CVE-2025-3755CRITICAL9.1Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Mitsubishi Electric Corporation ME...
CVE-2025-48749CRITICAL9.1Netwrix Directory Manager (formerly Imanami GroupID) v11.0.0.0 and before & after v.11.1.25134.03 inserts Sensitive Info...
CVE-2025-48929CRITICAL9.8The TeleMessage service through 2025-05-05 implements authentication through a long-lived credential (e.g., not a token ...
CVE-2025-45343CRITICAL9.8An issue in Tenda W18E v.2.0 v.16.01.0.11 allows an attacker to execute arbitrary code via the editing functionality of ...
CVE-2025-3357CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 19 could allow a remote attacker to execute arbitrary code du...
CVE-2025-5277CRITICAL9.6aws-mcp-server MCP server is vulnerable to command injection. An attacker can craft a prompt that once accessed by the M...
CVE-2025-5298CRITICAL9.8A vulnerability, which was classified as critical, was found in Campcodes Online Hospital Management System 1.0. Affecte...
CVE-2025-5295CRITICAL9.8A vulnerability classified as critical was found in FreeFloat FTP Server 1.0.0. This vulnerability affects unknown code ...
CVE-2025-27528CRITICAL9.1Deserialization of Untrusted Data vulnerability in Apache InLong. This issue affects Apache InLong: from 1.13.0 through...
CVE-2025-4009CRITICAL9.3The Evertz SDVN 3080ipx-10G is a High Bandwidth Ethernet Switching Fabric for Video Application. This device exposes a w...
CVE-2025-32440CRITICAL9.8NetAlertX is a network, presence scanner and alert framework. Prior to version 25.4.14, it is possible to bypass the aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now