2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-69562CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para...
CVE-2025-69559CRITICAL9.8code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php.
CVE-2025-69565CRITICAL9.8code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php.
CVE-2025-68670CRITICAL9.8xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi...
CVE-2025-70982CRITICAL9.9Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-59108CRITICAL9.2By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p...
CVE-2025-59103CRITICAL9.2The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis...
CVE-2025-59097CRITICAL9.3The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done...
CVE-2025-59091CRITICAL9.3Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn...
CVE-2025-59090CRITICAL9.3On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen...
CVE-2025-13374CRITICAL9.8The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ...
CVE-2025-13952CRITICAL9.8A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr...
CVE-2025-70457CRITICAL9.8A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up...
CVE-2025-52025CRITICAL9.4An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen...
CVE-2025-52024CRITICAL9.4A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin...
CVE-2025-70985CRITICAL9.1Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data...
CVE-2025-70983CRITICAL9.9Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ...
CVE-2025-67229CRITICAL9.8An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth...
CVE-2025-66719CRITICAL9.1An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck...
CVE-2025-4320CRITICAL10Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire...
CVE-2025-4319CRITICAL9.4Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne...
CVE-2025-15063CRITICAL9.8Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote atta...
CVE-2025-15061CRITICAL9.8Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allo...
CVE-2025-55705CRITICAL9.8This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg...
CVE-2025-54816CRITICAL9.8This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now