2025 CVE Vulnerabilities

45,326 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-21298CRITICAL9.8Windows OLE Remote Code Execution Vulnerability
CVE-2025-0463CRITICAL9.8A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified...
CVE-2025-0462CRITICAL9.8A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0 and classified as criti...
CVE-2025-20055CRITICAL9.8OS command injection vulnerability exists in network storage servers STEALTHONE D220/D340 provided by Y'S corporation. A...
CVE-2025-0070CRITICAL9.9SAP NetWeaver Application Server for ABAP and ABAP Platform allows an authenticated attacker to obtain illegitimate acce...
CVE-2025-0061CRITICAL9.1SAP BusinessObjects Business Intelligence Platform allows an unauthenticated attacker to perform session hijacking over ...
CVE-2025-22144CRITICAL9.8NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or ...
CVE-2025-22777CRITICAL9.8Deserialization of Untrusted Data vulnerability in StellarWP GiveWP give allows Object Injection.This issue affects Give...
CVE-2025-0107CRITICAL9.8An OS command injection vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to run arbitr...
CVE-2025-0105CRITICAL9.1An arbitrary file deletion vulnerability in Palo Alto Networks Expedition enables an unauthenticated attacker to delete ...
CVE-2025-22949CRITICAL9.8Tenda ac9 v1.0 firmware v15.03.05.19 is vulnerable to command injection in /goform/SetSambaCfg, which may lead to remote...
CVE-2025-22152CRITICAL9.4Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly valida...
CVE-2025-22946CRITICAL9.8Tenda ac9 v1.0 firmware v15.03.05.19 contains a stack overflow vulnerability in /goform/SetOnlineDevName, which may lead...
CVE-2025-23016CRITICAL9.3FastCGI fcgi2 (aka fcgi) 2.x through 2.4.4 has an integer overflow (and resultant heap-based buffer overflow) via crafte...
CVE-2025-22542CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ofek Nakar Virtual...
CVE-2025-22540CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in seballero Emailing...
CVE-2025-22504CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in jumpdemand 4ECPS Web Forms 4ecps-webforms allows Upload...
CVE-2025-0349CRITICAL9.8A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentContro...
CVE-2025-0347CRITICAL9.8A vulnerability was found in code-projects Admission Management System 1.0. It has been declared as critical. This vulne...
CVE-2025-0341CRITICAL9.8A vulnerability, which was classified as critical, has been found in CampCodes Computer Laboratory Management System 1.0...
CVE-2025-0340CRITICAL9.8A vulnerability classified as critical was found in code-projects Cinema Seat Reservation System 1.0. Affected by this v...
CVE-2025-0336CRITICAL9.8A vulnerability was found in Codezips Project Management System 1.0. It has been classified as critical. This affects an...
CVE-2025-0335CRITICAL9.8A vulnerability was found in code-projects Online Bike Rental System 1.0 and classified as critical. Affected by this is...
CVE-2025-0282CRITICAL9A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7...
CVE-2025-22137CRITICAL9.8Pingvin Share is a self-hosted file sharing platform and an alternative for WeTransfer. This vulnerability allows an aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now