2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-1188CRITICAL9.8A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by thi...
CVE-2025-1186CRITICAL9.8A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects ...
CVE-2025-26520CRITICAL9.8Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template paramete...
CVE-2025-1183CRITICAL9.8A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulner...
CVE-2025-25530CRITICAL9.8Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which...
CVE-2025-1044CRITICAL9.8Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas...
CVE-2025-24434CRITICAL9.1Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect A...
CVE-2025-21198CRITICAL9Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability
CVE-2025-1126CRITICAL9.3A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management ...
CVE-2025-24973CRITICAL9.3Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1...
CVE-2025-26492CRITICAL9.1In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources
CVE-2025-24956CRITICAL9.8A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a len...
CVE-2025-26410CRITICAL9.8The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password ca...
CVE-2025-0181CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-0180CRITICAL9.8The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. ...
CVE-2025-1177CRITICAL9.8A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import...
CVE-2025-1144CRITICAL9.8School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view ...
CVE-2025-1168CRITICAL9.8A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. Th...
CVE-2025-1167CRITICAL9.8A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected...
CVE-2025-1160CRITICAL9.8A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t...
CVE-2025-24016CRITICAL9.9Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ...
CVE-2025-24032CRITICAL9.2PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if ce...
CVE-2025-0316CRITICAL9.8The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including...
CVE-2025-24028CRITICAL9.6Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into...
CVE-2025-1113CRITICAL9.8A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the functi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now