2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-15578CRITICAL9.8Maypole versions from 2.10 through 2.13 for Perl generates session ids insecurely. The session id is seeded with the sys...
CVE-2025-32058CRITICAL9.3The Infotainment ECU manufactured by Bosch uses a RH850 module for CAN communication. RH850 is connected to infotainment...
CVE-2025-8572CRITICAL9.8The Truelysell Core plugin for WordPress is vulnerable to privilege escalation in versions less than, or equal to, 1.8.7...
CVE-2025-69633CRITICAL9.8A SQL Injection vulnerability in the Advanced Popup Creator (advancedpopupcreator) module for PrestaShop 1.1.26 through ...
CVE-2025-69770CRITICAL10A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execu...
CVE-2025-70314CRITICAL9.8webfsd 1.21 is vulnerable to a Buffer Overflow via a crafted request. This is due to the filename variable
CVE-2025-70981CRITICAL9.8CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds p...
CVE-2025-69634CRITICAL9Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges ...
CVE-2025-14014CRITICAL9.8Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software H...
CVE-2025-10969CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E...
CVE-2025-15573CRITICAL9.4The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th...
CVE-2025-14892CRITICAL9.8The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having a...
CVE-2025-67135CRITICAL9.8Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access contro...
CVE-2025-69872CRITICAL9.8DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces...
CVE-2025-70085CRITICAL9.8An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf...
CVE-2025-69874CRITICAL9.8nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t...
CVE-2025-64075CRITICAL10A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ...
CVE-2025-12059CRITICAL9.8Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry ...
CVE-2025-8668CRITICAL9.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So...
CVE-2025-8025CRITICAL9.8Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos...
CVE-2025-66277CRITICAL9.8A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ...
CVE-2025-7659CRITICAL9.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-52436CRITICAL9.6An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-11242CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In...
CVE-2025-66630CRITICAL9.4Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now