2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-63564CRITICAL9.8SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code...
CVE-2025-12999CRITICAL9.1UrlUtil.getBaseUrl builds the absolute URLs in a response — download links, icons, asset and API URLs — from the X-Forwa...
CVE-2025-66455CRITICAL9.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.2 and prior...
CVE-2025-53837CRITICAL9.9XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int...
CVE-2025-15399CRITICAL10IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 is vulnerable to cro...
CVE-2025-55787CRITICAL9.8In MailData Email Archiving System v4.2 and earlier, a SQL injection vulnerability exists.
CVE-2025-56563CRITICAL9.8A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith Satellite Tracker 1.0. The script accepts ...
CVE-2025-59953CRITICAL9.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. Starting in version 0.9.1 and prior...
CVE-2025-43936CRITICAL9.1Dell ObjectScale, versions prior to ObjectScale 4.4.0.0, contains an Improper Authentication vulnerability. An unauthent...
CVE-2025-67066CRITICAL9.8SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtyp...
CVE-2025-9314CRITICAL9.8The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in th...
CVE-2025-51679CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected ...
CVE-2025-70293CRITICAL9.8An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability exists in function ext4fs_get_b...
CVE-2025-70290CRITICAL9.8An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c...
CVE-2025-61165CRITICAL9.8An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac...
CVE-2025-61163CRITICAL9.8Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This...
CVE-2025-15689CRITICAL9.8Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.
CVE-2025-15688CRITICAL9.3Unauthenticated SQL Injection in Capella <= 2.5.5 versions.
CVE-2025-14600CRITICAL9.3An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access....
CVE-2025-59324CRITICAL9.1CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is ...
CVE-2025-59321CRITICAL9.8CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the syst...
CVE-2025-59326CRITICAL9.8CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file sys...
CVE-2025-41769CRITICAL9.8The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A...
CVE-2025-31114CRITICAL9.3Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex...
CVE-2025-15681CRITICAL9.2TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now