2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-34046CRITICAL10An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnera...
CVE-2025-34044CRITICAL9.4A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router ...
CVE-2025-34043CRITICAL10A remote command injection vulnerability exists in Vacron Network Video Recorder (NVR) devices v1.4 due to improper inpu...
CVE-2025-34042CRITICAL9.4An authenticated command injection vulnerability exists in the Beward N100 IP Camera firmware version M2.1.6.04C014 via ...
CVE-2025-53002CRITICAL9.8LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLa...
CVE-2025-29331CRITICAL9.8An issue in MHSanaei 3x-ui before v.2.5.3 and before allows a remote attacker to execute arbitrary code via the manageme...
CVE-2025-49003CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.11, a threat actor m...
CVE-2025-6561CRITICAL9.8Certain hybrid DVR models ((HBF-09KD and HBF-16NK)) from Hunt Electronic have an Exposure of Sensitive Information vulne...
CVE-2025-4334CRITICAL9.8The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and inclu...
CVE-2025-6668CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This aff...
CVE-2025-6665CRITICAL9.8A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by ...
CVE-2025-36038CRITICAL9.8IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to execute arbitrary code on the system with ...
CVE-2025-6621CRITICAL9.8A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSet...
CVE-2025-6620CRITICAL9.8A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the f...
CVE-2025-6619CRITICAL9.8A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerabili...
CVE-2025-6618CRITICAL9.8A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function S...
CVE-2025-52483CRITICAL9.8Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi...
CVE-2025-52480CRITICAL9.8Registrator is a GitHub app that automates creation of registration pull requests for julia packages to the General regi...
CVE-2025-49153CRITICAL9.3The affected products could allow an unauthenticated attacker to overwrite files and execute arbitrary code.
CVE-2025-49151CRITICAL9.3The affected products could allow an unauthenticated attacker to generate forged JSON Web Tokens (JWT) to bypass authent...
CVE-2025-20282CRITICAL10A vulnerability in an internal API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to upl...
CVE-2025-6612CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue af...
CVE-2025-6611CRITICAL9.8A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulne...
CVE-2025-20281CRITICAL10A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to exec...
CVE-2025-6543CRITICAL9.8Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Ga...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now