2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25196CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-25467CRITICAL9.8Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary...
CVE-2025-26617CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26613CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection ...
CVE-2025-26612CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26611CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26610CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26609CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26608CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26607CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26606CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26623CRITICAL9.8Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2025-22654CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious F...
CVE-2025-24895CRITICAL9.1CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is ba...
CVE-2025-24894CRITICAL9.1SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is base...
CVE-2025-1023CRITICAL9.8A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit...
CVE-2025-25222CRITICAL9.8The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v...
CVE-2025-25221CRITICAL9.8The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v...
CVE-2025-1380CRITICAL9.8A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is so...
CVE-2025-1379CRITICAL9.8A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. A...
CVE-2025-1387CRITICAL9.8Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers t...
CVE-2025-22290CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-22289CRITICAL9.8Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-uni...
CVE-2025-1355CRITICAL9.8A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulne...
CVE-2025-26793CRITICAL9.3The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with defaul...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now