2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12208CRITICAL9.8A vulnerability was found in SourceCodester Best House Rental Management System 1.0. This impacts the function login2 of...
CVE-2025-62959CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-...
CVE-2025-12285CRITICAL9.8Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12275CRITICAL9.8Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1....
CVE-2025-12220CRITICAL9.8Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12219CRITICAL9.8Vulnerable Components in Azure Access OS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12218CRITICAL9.1Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12217CRITICAL9.1SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-62717CRITICAL9.1Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification co...
CVE-2025-60803CRITICAL9.8Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulner...
CVE-2025-60554CRITICAL9.8D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60553CRITICAL9.8D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS...
CVE-2025-60548CRITICAL9.8D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formL...
CVE-2025-12176CRITICAL9.8Undocumented administrative accounts were getting created to facilitate access for applications running on board.This is...
CVE-2025-8536CRITICAL9.3A SQL injection vulnerability has been identified in DobryCMS. Improper neutralization of input provided by user into la...
CVE-2025-43995CRITICAL9.8Dell Storage Center - Dell Storage Manager, version(s) 20.1.21, contain(s) an Improper Authentication vulnerability. An ...
CVE-2025-11253CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aksis Technology I...
CVE-2025-6440CRITICAL9.8The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the...
CVE-2025-61934CRITICAL10A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. T...
CVE-2025-59503CRITICAL9.8Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a...
CVE-2025-59273CRITICAL9.8Improper access control in Azure Event Grid allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-58428CRITICAL9.9The TLS4B ATG system's SOAP-based interface is vulnerable due to its accessibility through the web services handler. Thi...
CVE-2025-11023CRITICAL9.8Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in ...
CVE-2025-47699CRITICAL9.9Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) in the Gallagher Morpho integration...
CVE-2025-12104CRITICAL9.8Outdated and Vulnerable UI Dependencies might potentially lead to exploitation.This issue affects BLU-IC2: through 1.19....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now