2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25349CRITICAL9.8PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem pa...
CVE-2025-0332CRITICAL9.8In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target...
CVE-2025-26361CRITICAL9.1A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26359CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o...
CVE-2025-26347CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq...
CVE-2025-26345CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq...
CVE-2025-26344CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than...
CVE-2025-26342CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o...
CVE-2025-26341CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o...
CVE-2025-26339CRITICAL9.8A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal...
CVE-2025-1100CRITICAL9.8A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allow...
CVE-2025-1188CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by thi...
CVE-2025-1186CRITICAL9.8A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects ...
CVE-2025-26520CRITICAL9.8Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template paramete...
CVE-2025-1183CRITICAL9.8A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulner...
CVE-2025-25530CRITICAL9.8Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which...
CVE-2025-1044CRITICAL9.8Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas...
CVE-2025-24434CRITICAL9.1Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect A...
CVE-2025-21198CRITICAL9Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
CVE-2025-1126CRITICAL9.3A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management ...
CVE-2025-24973CRITICAL9.3Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1...
CVE-2025-26492CRITICAL9.1In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
CVE-2025-24956CRITICAL9.8A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a len...
CVE-2025-26410CRITICAL9.8The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password ca...
CVE-2025-0181CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now