2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-58053CRITICAL9.8Galette is a membership management web application for non profit organizations. Prior to version 1.2.0, while updating ...
CVE-2025-34433CRITICAL9.3AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictabl...
CVE-2025-14952CRITICAL9.8A vulnerability was detected in Campcodes Supplier Management System 1.0. This affects an unknown function of the file /...
CVE-2025-14951CRITICAL9.8A security vulnerability has been detected in code-projects Scholars Tracking System 1.0. The impacted element is an unk...
CVE-2025-14950CRITICAL9.8A weakness has been identified in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio...
CVE-2025-1928CRITICAL9.1Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online...
CVE-2025-14940CRITICAL9.8A vulnerability was determined in code-projects Scholars Tracking System 1.0. The affected element is an unknown functio...
CVE-2025-67843CRITICAL9.8A Server-Side Template Injection (SSTI) vulnerability in the MDX Rendering Engine in Mintlify Platform before 2025-11-15...
CVE-2025-14733CRITICAL9.8An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac...
CVE-2025-64675CRITICAL9.6Improper neutralization of input during web page generation ('cross-site scripting') in Azure Cosmos DB allows an unauth...
CVE-2025-68398CRITICAL9.1Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration re...
CVE-2025-65041CRITICAL9.8Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-65037CRITICAL10Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to exe...
CVE-2025-34449CRITICAL9.1Genymobile/scrcpy versions up to and including 3.3.3, prior to commit 3e40b24, contain a buffer overflow vulnerability i...
CVE-2025-14850CRITICAL9.1Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
CVE-2025-14849CRITICAL9.8Advantech WebAccess/SCADA  is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute ar...
CVE-2025-56157CRITICAL9.8Default credentials in Dify thru 1.5.1. PostgreSQL username and password specified in the docker-compose.yaml file inclu...
CVE-2025-64236CRITICAL9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in AmentoTech Tuturn allows Authentication Abuse....
CVE-2025-14879CRITICAL9.8A weakness has been identified in Tenda WH450 1.0.0.18. Affected is an unknown function of the file /goform/onSSIDChange...
CVE-2025-63389CRITICAL9.8A critical authentication bypass vulnerability exists in Ollama platform's API endpoints in versions prior to and includ...
CVE-2025-63388CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-f...
CVE-2025-63386CRITICAL9.1A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/setup en...
CVE-2025-14878CRITICAL9.8A security flaw has been discovered in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/wirele...
CVE-2025-14877CRITICAL9.8A vulnerability was identified in Campcodes Supplier Management System 1.0. This affects an unknown function of the file...
CVE-2025-7358CRITICAL9.8Use of Hard-coded Credentials vulnerability in Utarit Informatics Services Inc. SoliClub allows Authentication Abuse. T...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now