2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-36157CRITICAL9.1IBM Jazz Foundation 7.0.2 to 7.0.2 iFix035, 7.0.3 to 7.0.3 iFix018, and 7.1.0 to 7.1.0 iFix004 could allow an unauthenti...
CVE-2025-5821CRITICAL9.8The Case Theme User plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1....
CVE-2025-5352CRITICAL9.6A critical stored Cross-Site Scripting (XSS) vulnerability exists in the Analytics component of lunary-ai/lunary version...
CVE-2025-7642CRITICAL9.8The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due...
CVE-2025-43766CRITICAL9.8The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2...
CVE-2025-4609CRITICAL9.6Incorrect handle provided in unspecified circumstances in Mojo in Google Chrome on Windows prior to 136.0.7103.113 allow...
CVE-2025-26496CRITICAL9.3Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Salesforce Tableau Server, Tableau Deskto...
CVE-2025-57801CRITICAL9.1gnark is a zero-knowledge proof system framework. In versions prior to 0.14.0, the Verify function in eddsa.go and ecdsa...
CVE-2025-51092CRITICAL9.8The LogIn-SignUp project by VishnuSivadasVS is vulnerable to SQL Injection due to unsafe construction of SQL queries in ...
CVE-2025-55613CRITICAL9.8Tenda O3V2 1.0.0.12(3880) is vulnerable to Buffer Overflow in the fromSafeSetMacFilter function via the mac parameter.
CVE-2025-57105CRITICAL9.8The DI-7400G+ router has a command injection vulnerability, which allows attackers to execute arbitrary commands on the ...
CVE-2025-55637CRITICAL9.8Reolink Smart 2K+ Plug-in Wi-Fi Video Doorbell with Chime - firmware v3.0.0.4662_2503122283 was discovered to contain a ...
CVE-2025-55619CRITICAL9.8Reolink v4.54.0.4.20250526 was discovered to contain a hardcoded encryption key and initialization vector. An attacker c...
CVE-2025-55398CRITICAL9.8An issue was discovered in mouse07410 asn1c thru 0.9.29 (2025-03-20) - a fork of vlm asn1c. In UPER (Unaligned Packed En...
CVE-2025-52095CRITICAL9.8An issue in PDQ Smart Deploy V.3.0.2040 allows an attacker to escalate privileges via the Credential encryption routines...
CVE-2025-29366CRITICAL9.8In mupen64plus v2.6.0 there is an array overflow vulnerability in the write_rdram_regs and write_rdram_regs functions, w...
CVE-2025-29365CRITICAL9.8spimsimulator spim v9.1.24 and before is vulnerable to Buffer Overflow in READ_STRING_SYSCALL.
CVE-2025-9254CRITICAL9.8WebITR developed by Uniong has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to log ...
CVE-2025-53795CRITICAL9.8Improper authorization in Microsoft PC Manager allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-53763CRITICAL9.8Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-3128CRITICAL9.8A remote unauthenticated attacker who has bypassed authentication could execute arbitrary OS commands to disclose, tamp...
CVE-2025-52352CRITICAL9.8Aikaan IoT management platform v3.25.0325-5-g2e9c59796 provides a configuration to disable user sign-up in distributed d...
CVE-2025-9311CRITICAL9.8A vulnerability was identified in itsourcecode Apartment Management System 1.0. Affected by this issue is some unknown f...
CVE-2025-57754CRITICAL9.8eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is ex...
CVE-2025-9307CRITICAL9.8A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now