2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21298 | CRITICAL | 9.8 | 80.9% | Jan 14, 2025 | Windows OLE Remote Code Execution Vulnerability |
| CVE-2025-0463 | CRITICAL | 9.8 | 0.4% | Jan 14, 2025 | A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified... |
| CVE-2025-0462 | CRITICAL | 9.8 | 0.5% | Jan 14, 2025 | A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as criti... |
| CVE-2025-20055 | CRITICAL | 9.8 | 1.1% | Jan 14, 2025 | OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. A... |
| CVE-2025-0070 | CRITICAL | 9.9 | 0.7% | Jan 14, 2025 | SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate acce... |
| CVE-2025-0061 | CRITICAL | 9.1 | 0.5% | Jan 14, 2025 | SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over ... |
| CVE-2025-22144 | CRITICAL | 9.8 | 0.7% | Jan 13, 2025 | NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or ... |
| CVE-2025-22777 | CRITICAL | 9.8 | 0.9% | Jan 13, 2025 | Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects Give... |
| CVE-2025-0107 | CRITICAL | 9.8 | 77.7% | Jan 11, 2025 | An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitr... |
| CVE-2025-0105 | CRITICAL | 9.1 | 13.0% | Jan 11, 2025 | An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete ... |
| CVE-2025-22949 | CRITICAL | 9.8 | 1.9% | Jan 10, 2025 | Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote... |
| CVE-2025-22152 | CRITICAL | 9.4 | 0.6% | Jan 10, 2025 | Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly valida... |
| CVE-2025-22946 | CRITICAL | 9.8 | 0.9% | Jan 10, 2025 | Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead... |
| CVE-2025-23016 | CRITICAL | 9.3 | 0.6% | Jan 10, 2025 | FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafte... |
| CVE-2025-22542 | CRITICAL | 9.3 | 0.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ofek Nakar Virtual... |
| CVE-2025-22540 | CRITICAL | 9.3 | 0.4% | Jan 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in seballero Emailing... |
| CVE-2025-22504 | CRITICAL | 10 | 0.5% | Jan 9, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload... |
| CVE-2025-0349 | CRITICAL | 9.8 | 1.8% | Jan 9, 2025 | A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentContro... |
| CVE-2025-0347 | CRITICAL | 9.8 | 0.7% | Jan 9, 2025 | A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulne... |
| CVE-2025-0341 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0... |
| CVE-2025-0340 | CRITICAL | 9.8 | 0.6% | Jan 9, 2025 | A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this v... |
| CVE-2025-0336 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an... |
| CVE-2025-0335 | CRITICAL | 9.8 | 0.5% | Jan 9, 2025 | A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this is... |
| CVE-2025-0282 | CRITICAL | 9 | 100.0% | Jan 8, 2025 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7... |
| CVE-2025-22137 | CRITICAL | 9.8 | 0.6% | Jan 8, 2025 | Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now