2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-40554CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could...
CVE-2025-40553CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ...
CVE-2025-40552CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would ...
CVE-2025-40551CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ...
CVE-2025-40536CRITICAL9.8SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could...
CVE-2025-21589CRITICAL9.8An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a...
CVE-2025-14988CRITICAL10A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co...
CVE-2025-69564CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres...
CVE-2025-69563CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete...
CVE-2025-69562CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para...
CVE-2025-69559CRITICAL9.8code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
CVE-2025-69565CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
CVE-2025-68670CRITICAL9.8xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi...
CVE-2025-70982CRITICAL9.9Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-59108CRITICAL9.2By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p...
CVE-2025-59103CRITICAL9.2The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis...
CVE-2025-59097CRITICAL9.3The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done...
CVE-2025-59091CRITICAL9.3Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn...
CVE-2025-59090CRITICAL9.3On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen...
CVE-2025-13374CRITICAL9.8The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-13952CRITICAL9.8A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr...
CVE-2025-70457CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up...
CVE-2025-52025CRITICAL9.4An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen...
CVE-2025-52024CRITICAL9.4A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin...
CVE-2025-70985CRITICAL9.1Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now