2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-0491CRITICAL9.8A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown fun...
CVE-2025-0487CRITICAL9.8A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some...
CVE-2025-0486CRITICAL9.8A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been declared as critical. Affected by this vulnerabil...
CVE-2025-22146CRITICAL9.1Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in t...
CVE-2025-0502CRITICAL9.1Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS...
CVE-2025-22968CRITICAL9.8An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account witho...
CVE-2025-22785CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course B...
CVE-2025-22782CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-...
CVE-2025-23061CRITICAL9.8Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO...
CVE-2025-21311CRITICAL9.8Windows NTLM V1 Elevation of Privilege Vulnerability
CVE-2025-21307CRITICAL9.8Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
CVE-2025-21298CRITICAL9.8Windows OLE Remote Code Execution Vulnerability
CVE-2025-0463CRITICAL9.8A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified...
CVE-2025-0462CRITICAL9.8A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as criti...
CVE-2025-20055CRITICAL9.8OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. A...
CVE-2025-0070CRITICAL9.9SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate acce...
CVE-2025-0061CRITICAL9.1SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over ...
CVE-2025-22144CRITICAL9.8NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or ...
CVE-2025-22777CRITICAL9.8Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects Give...
CVE-2025-0107CRITICAL9.8An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitr...
CVE-2025-0105CRITICAL9.1An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete ...
CVE-2025-22949CRITICAL9.8Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote...
CVE-2025-22152CRITICAL9.4Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly valida...
CVE-2025-22946CRITICAL9.8Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead...
CVE-2025-23016CRITICAL9.3FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafte...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now