2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-33024CRITICAL9.9A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-32469CRITICAL9.9A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-26390CRITICAL9.8A vulnerability has been identified in OZW672 (All versions < V6.0), OZW772 (All versions < V6.0). The web service of af...
CVE-2025-26389CRITICAL9.8A vulnerability has been identified in OZW672 (All versions < V8.0), OZW772 (All versions < V8.0). The web service in af...
CVE-2025-4632CRITICAL9.8Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 2...
CVE-2025-42999CRITICAL9.1SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious c...
CVE-2025-30012CRITICAL9.8The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which al...
CVE-2025-30448CRITICAL9.1This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17....
CVE-2025-30436CRITICAL9.1This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.4 and iPadOS 1...
CVE-2025-3659CRITICAL9.4Improper authentication handling was identified in a set of HTTP POST requests affecting the following product families:...
CVE-2025-47682CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Al...
CVE-2025-45779CRITICAL9.8Tenda AC10 V1.0re_V15.03.06.46 is vulnerable to Buffer Overflow in the formSetPPTPUserList handler via the list POST par...
CVE-2025-44830CRITICAL9.8EngineerCMS v1.02 through v.2.0.5 has a SQL injection vulnerability in the /project/addprojtemplet interface.
CVE-2025-44022CRITICAL9.8An issue in vvveb CMS v.1.0.6 allows a remote attacker to execute arbitrary code via the Plugin mechanism.
CVE-2025-26846CRITICAL9.8An issue was discovered in Znuny before 7.1.4. Permissions are not checked properly when using the Generic Interface to ...
CVE-2025-4559CRITICAL9.8The ISOinsight from Netvision has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arb...
CVE-2025-4558CRITICAL9.8The GPM from WormHole Tech has an Unverified Password Change vulnerability, allowing unauthenticated remote attackers to...
CVE-2025-4557CRITICAL9.1The specific APIs of Parking Management System from ZONG YU has a Missing Authentication vulnerability, allowing unauthe...
CVE-2025-4556CRITICAL9.8The web management interface of Okcat Parking Management Platform from ZONG YU has an Arbitrary File Upload vulnerabilit...
CVE-2025-4555CRITICAL9.8The web management interface of Okcat Parking Management Platform from ZONG YU has a Missing Authentication vulnerabilit...
CVE-2025-4554CRITICAL9.8A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Th...
CVE-2025-4553CRITICAL9.8A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by...
CVE-2025-4550CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Apartment Visitors Management System 1.0...
CVE-2025-4549CRITICAL9.8A vulnerability classified as critical was found in Campcodes Online Food Ordering System 1.0. This vulnerability affect...
CVE-2025-4548CRITICAL9.8A vulnerability classified as critical has been found in Campcodes Online Food Ordering System 1.0. This affects an unkn...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now