2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-26623CRITICAL9.8Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada...
CVE-2025-22654CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious F...
CVE-2025-24895CRITICAL9.1CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is ba...
CVE-2025-24894CRITICAL9.1SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is base...
CVE-2025-1023CRITICAL9.8A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit...
CVE-2025-25222CRITICAL9.8The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v...
CVE-2025-25221CRITICAL9.8The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v...
CVE-2025-1380CRITICAL9.8A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is so...
CVE-2025-1379CRITICAL9.8A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. A...
CVE-2025-1387CRITICAL9.8Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers t...
CVE-2025-22290CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ...
CVE-2025-22289CRITICAL9.8Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-uni...
CVE-2025-1355CRITICAL9.8A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulne...
CVE-2025-26793CRITICAL9.3The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with defaul...
CVE-2025-1302CRITICAL9.8Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input ...
CVE-2025-26508CRITICAL9.8Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot...
CVE-2025-26507CRITICAL9.8Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot...
CVE-2025-26506CRITICAL9.8Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot...
CVE-2025-24607CRITICAL9.8Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configu...
CVE-2025-0867CRITICAL9.9The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that...
CVE-2025-1298CRITICAL9.8Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.
CVE-2025-22630CRITICAL9.9Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widg...
CVE-2025-25067CRITICAL9.8mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrar...
CVE-2025-24865CRITICAL9.8The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an...
CVE-2025-24861CRITICAL9.8An attacker may inject commands via specially-crafted post requests.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now