2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66956CRITICAL9.9Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t...
CVE-2025-67039CRITICAL9.8An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe...
CVE-2025-67038CRITICAL9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ...
CVE-2025-69615CRITICAL9.1Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n...
CVE-2025-69614CRITICAL9.4Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets...
CVE-2025-56422CRITICAL9.8A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o...
CVE-2025-41709CRITICAL9.8An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a...
CVE-2025-40943CRITICAL9.6Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug...
CVE-2025-11158CRITICAL9.1Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric...
CVE-2025-70039CRITICAL9.8An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag...
CVE-2025-70046CRITICAL9.8An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro...
CVE-2025-70042CRITICAL9.8An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.
CVE-2025-40639CRITICAL9.8A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up...
CVE-2025-41765CRITICAL9.1Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to...
CVE-2025-41764CRITICAL9.1Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to...
CVE-2025-59543CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab...
CVE-2025-59542CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab...
CVE-2025-55289CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored XSS vulnerability in Chamilo LMS (V...
CVE-2025-70948CRITICAL9.3A host header injection vulnerability in the mailer component of @perfood/couch-auth v0.26.0 allows attackers to obtain ...
CVE-2025-55208CRITICAL9Chamilo is a learning management system. Versions prior to 1.11.34 have a Stored XSS through insecure file uploads in `S...
CVE-2025-29165CRITICAL9.8An issue in D-Link DIR-1253 MESH V1.6.1684 allows an attacker to escalate privileges via the etc/shadow.sample component
CVE-2025-70233CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetEnableWizard.
CVE-2025-70232CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetMACFilter.
CVE-2025-70231CRITICAL9.8D-Link DIR-513 version 1.10 contains a critical-level vulnerability. When processing POST requests related to verificati...
CVE-2025-70230CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetDDNS.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now