2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-41687CRITICAL9.8An unauthenticated remote attacker may use a stack based buffer overflow in the u-link Management API to gain full acces...
CVE-2025-8070CRITICAL9.2The Windows service configuration of ABP and AES contains an unquoted ImagePath registry value vulnerability. This allow...
CVE-2025-54455CRITICAL9.8Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ...
CVE-2025-54454CRITICAL9.8Use of Hard-coded Credentials vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This ...
CVE-2025-54453CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54452CRITICAL9.8Improper Authentication vulnerability in Samsung Electronics MagicINFO 9 Server allows Authentication Bypass.This issue ...
CVE-2025-54451CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows...
CVE-2025-54450CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54449CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54448CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54447CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54446CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54445CRITICAL9.8Improper Restriction of XML External Entity Reference vulnerability in Samsung Electronics MagicINFO 9 Server allows Ser...
CVE-2025-54444CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54443CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54442CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54440CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Inje...
CVE-2025-54438CRITICAL9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Samsung Electronics Magi...
CVE-2025-54120CRITICAL9.3PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,...
CVE-2025-8044CRITICAL9.8Memory safety bugs present in Firefox 140 and Thunderbird 140. Some of these bugs showed evidence of memory corruption a...
CVE-2025-8043CRITICAL9.8Focus incorrectly truncated URLs towards the beginning instead of around the origin. This vulnerability was fixed in Fir...
CVE-2025-8038CRITICAL9.8Thunderbird ignored paths when checking the validity of navigations in a frame. This vulnerability was fixed in Firefox ...
CVE-2025-8037CRITICAL9.1Setting a nameless cookie with an equals sign in the value shadowed other cookies. Even if the nameless cookie was set o...
CVE-2025-8031CRITICAL9.8The `username:password` part was not correctly stripped from URLs in CSP reports potentially leaking HTTP Basic Authenti...
CVE-2025-8028CRITICAL9.8On arm64, a WASM `br_table` instruction with a lot of entries could lead to the label being too far from the instruction...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now