2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1283CRITICAL9.8The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na...
CVE-2025-1127CRITICAL9.1The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the co...
CVE-2025-25389CRITICAL9.8A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allow...
CVE-2025-25388CRITICAL9.8A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which all...
CVE-2025-0896CRITICAL9.8Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. Thi...
CVE-2025-25286CRITICAL9.8Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior t...
CVE-2025-1226CRITICAL9.8A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown...
CVE-2025-0108CRITICAL9.1An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network acce...
CVE-2025-25343CRITICAL9.8Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function.
CVE-2025-25746CRITICAL9.8D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param...
CVE-2025-25744CRITICAL9.8D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param...
CVE-2025-25742CRITICAL9.8D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPasswor...
CVE-2025-25182CRITICAL9.4Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and p...
CVE-2025-25351CRITICAL9.8PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense...
CVE-2025-25349CRITICAL9.8PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem pa...
CVE-2025-0332CRITICAL9.8In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target...
CVE-2025-26361CRITICAL9.1A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26359CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o...
CVE-2025-26347CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq...
CVE-2025-26345CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq...
CVE-2025-26344CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than...
CVE-2025-26342CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o...
CVE-2025-26341CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o...
CVE-2025-26339CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal...
CVE-2025-1100CRITICAL9.8A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allow...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now