2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-59304CRITICAL9.8A directory traversal issue in Swetrix Web Analytics API 3.1.1 before 7d8b972 allows a remote attacker to achieve Remote...
CVE-2025-35434CRITICAL9.8CISA Thorium does not validate TLS certificates when connecting to Elasticsearch. An unauthenticated attacker with acces...
CVE-2025-10603CRITICAL9.8A vulnerability was determined in PHPGurukul Online Discussion Forum 1.0. Affected by this issue is some unknown functio...
CVE-2025-10601CRITICAL9.8A vulnerability has been found in SourceCodester Online Exam Form Submission 1.0. Affected is an unknown function of the...
CVE-2025-10600CRITICAL9.8A flaw has been found in SourceCodester Online Exam Form Submission 1.0. This impacts an unknown function of the file /r...
CVE-2025-10599CRITICAL9.8A security flaw has been discovered in itsourcecode Web-Based Internet Laboratory Management System 1.0. Impacted is the...
CVE-2025-10598CRITICAL9.8A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown p...
CVE-2025-10597CRITICAL9.8A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vuln...
CVE-2025-10596CRITICAL9.8A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /i...
CVE-2025-8077CRITICAL9.8A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default pass...
CVE-2025-10439CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics...
CVE-2025-10156CRITICAL9.8An Improper Handling of Exceptional Conditions vulnerability in the ZIP archive scanning component of mmaitre314 pickles...
CVE-2025-59458CRITICAL9.8In JetBrains Junie before 252.284.66, 251.284.66, 243.284.66, 252.284.61, 251.284.61, 243.284.61, 252.284.50, 252.284.54...
CVE-2025-9242CRITICAL9.8An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attac...
CVE-2025-9972CRITICAL9.8Certain models of Industrial Cellular Gateway developed by Planet Technology have an OS Command Injection vulnerability,...
CVE-2025-9971CRITICAL9.8Certain models of Industrial Cellular Gateway developed by Planet Technology have a Missing Authentication vulnerability...
CVE-2025-54391CRITICAL9.1A vulnerability in the EnableTwoFactorAuthRequest SOAP endpoint of Zimbra Collaboration (ZCS) allows an attacker with va...
CVE-2025-10565CRITICAL9.8A vulnerability was determined in Campcodes Grocery Sales and Inventory System 1.0. Affected by this vulnerability is an...
CVE-2025-10564CRITICAL9.8A vulnerability was found in Campcodes Grocery Sales and Inventory System 1.0. Affected is an unknown function of the fi...
CVE-2025-57631CRITICAL9.8SQL Injection vulnerability in TDuckCloud v.5.1 allows a remote attacker to execute arbitrary code via the Add a file up...
CVE-2025-34186CRITICAL9.8Ilevia EVE X1/X5 Server version ≤ 4.7.18.0.eden contains a vulnerability in its authentication mechanism. Unsanitized in...
CVE-2025-34184CRITICAL9.8Ilevia EVE X1 Server version ≤ 4.7.18.0.eden contains an unauthenticated OS command injection vulnerability in the /ajax...
CVE-2025-10563CRITICAL9.8A vulnerability has been found in Campcodes Grocery Sales and Inventory System 1.0. This impacts an unknown function of ...
CVE-2025-56557CRITICAL9.1An issue discovered in the Tuya Smart Life App 5.6.1 allows attackers to unprivileged control Matter devices via the Mat...
CVE-2025-10562CRITICAL9.8A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This affects an unknown function of the file ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now