2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-8752CRITICAL9.8A vulnerability was found in wangzhixuan spring-shiro-training up to 94812c1fd8f7fe796c931f4984ff1aa0671ab562. It has be...
CVE-2025-54997CRITICAL9.1OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certifi...
CVE-2025-6573CRITICAL9.8Kernel software installed and running inside an untrusted/rich execution environment (REE) could leak information from t...
CVE-2025-5095CRITICAL9.8Burk Technology ARC Solo's password change mechanism can be utilized without proper authentication procedures, allowing...
CVE-2025-52913CRITICAL9.8A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP2 (9.8.2.12) could allo...
CVE-2025-8284CRITICAL9.8By default, the Packet Power Monitoring and Control Web Interface do not enforce authentication mechanisms. This vulner...
CVE-2025-46414CRITICAL9.2The affected product does not limit the number of attempts for inputting the correct PIN for a registered product, whic...
CVE-2025-8731CRITICAL9.8A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown par...
CVE-2025-8356CRITICAL9.8In Xerox FreeFlow Core version 8.0.4, an attacker can exploit a Path Traversal vulnerability to access unauthorized file...
CVE-2025-8730CRITICAL9.8A vulnerability was found in Belkin F9K1009 and F9K1010 2.00.04/2.00.09 and classified as critical. Affected by this iss...
CVE-2025-8729CRITICAL9.1A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is t...
CVE-2025-53606CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache Seata (incubating). This issue affects Apache Seata (incubati...
CVE-2025-48913CRITICAL9.8If untrusted users are allowed to configure JMS for Apache CXF, previously they could use RMI or LDAP URLs, potentially ...
CVE-2025-54887CRITICAL9.1jwe is a Ruby implementation of the RFC 7516 JSON Web Encryption (JWE) standard. In versions 1.1.0 and below, authentica...
CVE-2025-54952CRITICAL9.8An integer overflow vulnerability in the loading of ExecuTorch models can cause smaller-than-expected memory regions to ...
CVE-2025-54951CRITICAL9.8A group of related buffer overflow vulnerabilities in the loading of ExecuTorch models can cause the runtime to crash an...
CVE-2025-54950CRITICAL9.8An out-of-bounds access vulnerability in the loading of ExecuTorch models can cause the runtime to crash and potentially...
CVE-2025-54949CRITICAL9.8A heap buffer overflow vulnerability in the loading of ExecuTorch models can potentially result in code execution or oth...
CVE-2025-30405CRITICAL9.8An integer overflow vulnerability in the loading of ExecuTorch models can cause objects to be placed outside their alloc...
CVE-2025-30404CRITICAL9.8An integer overflow vulnerability in the loading of ExecuTorch models can cause overlapping allocations, potentially res...
CVE-2025-53792CRITICAL9.1Azure Portal Elevation of Privilege Vulnerability
CVE-2025-53767CRITICAL10Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-45765CRITICAL9.1ruby-jwt v3.0.0.beta1 was discovered to contain weak encryption. NOTE: the Supplier's perspective is "keysize is not som...
CVE-2025-50692CRITICAL9.8FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.
CVE-2025-34152CRITICAL9.4An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now