2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-40600CRITICAL9.8Use of Externally-Controlled Format String vulnerability in the SonicOS SSL VPN interface allows a remote unauthenticate...
CVE-2025-53102CRITICAL9.8Discourse is an open-source community discussion platform. Prior to version 3.4.7 on the `stable` branch and version 3.5...
CVE-2025-44136CRITICAL9.8MapTiler Tileserver-php v2.0 is vulnerable to Cross Site Scripting (XSS). The GET parameter "layer" is reflected in an e...
CVE-2025-50738CRITICAL9.8The Memos application, up to version v0.24.3, allows for the embedding of markdown images with arbitrary URLs. When a us...
CVE-2025-46059CRITICAL9.8langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component....
CVE-2025-7458CRITICAL9.1An integer overflow in the sqlite3KeyInfoFromExprList function in SQLite versions 3.39.2 through 3.41.1 allows an attack...
CVE-2025-40682CRITICAL9.8SQL injection vulnerability in Human Resource Management System version 1.0, which allows an attacker to retrieve, creat...
CVE-2025-53082CRITICAL9.1An 'Arbitrary File Deletion' in Samsung DMS(Data Management Server) allows attackers to delete arbitrary files from unin...
CVE-2025-53081CRITICAL9.1An 'Arbitrary File Creation' in Samsung DMS(Data Management Server) allows attackers to create arbitrary files in uninte...
CVE-2025-8264CRITICAL9Versions of the package z-push/z-push-dev before 2.7.6 are vulnerable to SQL Injection due to unparameterized queries in...
CVE-2025-53078CRITICAL9.8Deserialization of Untrusted Data in Samsung DMS(Data Management Server) allows attackers to execute arbitrary code via ...
CVE-2025-54428CRITICAL9.8RevelaCode is an AI-powered faith-tech project that decodes biblical verses, prophecies and global events into accessibl...
CVE-2025-54426CRITICAL9.9Polkadot Frontier is an Ethereum and EVM compatibility layer for Polkadot and Substrate. In versions prior to commit 36f...
CVE-2025-54419CRITICAL10A SAML library not dependent on any frameworks that runs in Node. In version 5.0.1, Node-SAML loads the assertion from t...
CVE-2025-54299CRITICAL9.4A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.
CVE-2025-54298CRITICAL9.4A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.
CVE-2025-43023CRITICAL9.1A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documentation. This...
CVE-2025-54531CRITICAL9.4In JetBrains TeamCity before 2025.07 path traversal was possible via plugin unpacking on Windows
CVE-2025-54530CRITICAL9.8In JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissions
CVE-2025-54418CRITICAL9.8CodeIgniter is a PHP full-stack web framework. A command injection vulnerability present in versions prior to 4.6.2 affe...
CVE-2025-53696CRITICAL9.3iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the ...
CVE-2025-30125CRITICAL9.8An issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. All dashcams were shipped with the same default crede...
CVE-2025-8279CRITICAL9.8Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query...
CVE-2025-53695CRITICAL9.4OS Command Injection in iSTAR Ultra products web application allows an authenticated attacker to gain even more privileg...
CVE-2025-30133CRITICAL9.8An issue was discovered on IROAD Dashcam FX2 devices. Bypass of Device Pairing/Registration can occur. It requires devic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now