2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-14265CRITICAL9.1In versions of ScreenConnect™ prior to 25.8, server-side validation and integrity checks within the extension subsystem ...
CVE-2025-14515CRITICAL9.8A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown...
CVE-2025-14514CRITICAL9.8A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/ad...
CVE-2025-13764CRITICAL9.8The WP CarDealer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.16...
CVE-2025-67511CRITICAL9.6Cybersecurity AI (CAI) is an open-source framework for building and deploying AI-powered offensive and defensive automat...
CVE-2025-67510CRITICAL9.4Neuron is a PHP framework for creating and orchestrating AI Agents. In versions 2.8.11 and below, the MySQLWriteTool exe...
CVE-2025-65294CRITICAL9.8Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented r...
CVE-2025-65830CRITICAL9.1Due to a lack of certificate validation, all traffic from the mobile application can be intercepted. As a result, an adv...
CVE-2025-65827CRITICAL9.1The mobile application is configured to allow clear text traffic to all domains and communicates with an API server over...
CVE-2025-65826CRITICAL9.8The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retri...
CVE-2025-65823CRITICAL9.8The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was d...
CVE-2025-65820CRITICAL9.8An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mob...
CVE-2025-65602CRITICAL9.8A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbi...
CVE-2025-64539CRITICAL9.3Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64538CRITICAL9.3Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64537CRITICAL9.3Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-13607CRITICAL9.4A malicious actor can access camera configuration information, including account credentials, without authenticating whe...
CVE-2025-65792CRITICAL9.1DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
CVE-2025-34394CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser...
CVE-2025-34393CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify t...
CVE-2025-34392CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL def...
CVE-2025-13184CRITICAL9.8Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw...
CVE-2025-13953CRITICAL9.3Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D...
CVE-2025-41732CRITICAL9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary d...
CVE-2025-41730CRITICAL9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now