2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27797CRITICAL9.8OS command injection vulnerability in the specific service exists in Wi-Fi AP UNIT 'AC-WPS-11ac series'. If exploited, a...
CVE-2025-32461CRITICAL9.9wikiplugin_includetpl in lib/wiki-plugins/wikiplugin_includetpl.php in Tiki before 28.3 mishandles input to an eval. The...
CVE-2025-32460CRITICAL9.1GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportVie...
CVE-2025-30282CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Authentication vulnerability that c...
CVE-2025-30281CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-24447CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerabili...
CVE-2025-24446CRITICAL9.1ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-22871CRITICAL9.1The net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. This can permit...
CVE-2025-25226CRITICAL9.8Improper handling of identifiers lead to a SQL injection vulnerability in the quoteNameStr method of the database packag...
CVE-2025-32028CRITICAL9.9HAX CMS PHP allows you to manage your microsite universe with PHP backend. Multiple file upload functions within the HAX...
CVE-2025-32020CRITICAL9.3The crud-query-parser library parses query parameters from HTTP requests and converts them to database queries. Improper...
CVE-2025-22466CRITICAL9.6Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthentica...
CVE-2025-31330CRITICAL9.9SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function mo...
CVE-2025-30016CRITICAL9.8SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vul...
CVE-2025-27429CRITICAL9.9SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. T...
CVE-2025-2004CRITICAL9.1The Simple WP Events plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat...
CVE-2025-3401CRITICAL9.8A vulnerability has been found in ESAFENET CDG 5.6.3.154.205_20250114 and classified as critical. This vulnerability aff...
CVE-2025-3400CRITICAL9.8A vulnerability, which was classified as critical, was found in ESAFENET CDG 5.6.3.154.205_20250114. This affects an unk...
CVE-2025-3399CRITICAL9.8A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5.6.3.154.205_20250114. Affected by th...
CVE-2025-3398CRITICAL9.8A vulnerability classified as critical was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the funct...
CVE-2025-3363CRITICAL9.8The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac...
CVE-2025-3362CRITICAL9.8The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac...
CVE-2025-3361CRITICAL9.8The web service of iSherlock from HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attac...
CVE-2025-3384CRITICAL9.8A vulnerability was found in 1000 Projects Human Resource Management System 1.0. It has been classified as critical. Aff...
CVE-2025-3383CRITICAL9.8A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0 and classified as critical....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now