2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1302CRITICAL9.8Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input ...
CVE-2025-26508CRITICAL9.8Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot...
CVE-2025-26507CRITICAL9.8Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot...
CVE-2025-26506CRITICAL9.8Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot...
CVE-2025-24607CRITICAL9.8Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configu...
CVE-2025-0867CRITICAL9.9The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that...
CVE-2025-1298CRITICAL9.8Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.
CVE-2025-22630CRITICAL9.9Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widg...
CVE-2025-25067CRITICAL9.8mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrar...
CVE-2025-24865CRITICAL9.8The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an...
CVE-2025-24861CRITICAL9.8An attacker may inject commands via specially-crafted post requests.
CVE-2025-1283CRITICAL9.8The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na...
CVE-2025-1127CRITICAL9.1The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the co...
CVE-2025-25389CRITICAL9.8A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allow...
CVE-2025-25388CRITICAL9.8A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which all...
CVE-2025-0896CRITICAL9.8Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. Thi...
CVE-2025-25286CRITICAL9.8Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior t...
CVE-2025-1226CRITICAL9.8A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown...
CVE-2025-0108CRITICAL9.1An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network acce...
CVE-2025-25343CRITICAL9.8Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
CVE-2025-25746CRITICAL9.8D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param...
CVE-2025-25744CRITICAL9.8D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param...
CVE-2025-25742CRITICAL9.8D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPasswor...
CVE-2025-25182CRITICAL9.4Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and p...
CVE-2025-25351CRITICAL9.8PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now