2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10969CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Farktor Software E...
CVE-2025-15573CRITICAL9.4The affected devices do not validate the server certificate when connecting to the SolaX Cloud MQTTS server hosted in th...
CVE-2025-14892CRITICAL9.8The Prime Listing Manager WordPress plugin through 1.1 allows an attacker to gain administrative access without having a...
CVE-2025-67135CRITICAL9.8Weak Security in the PF-50 1.2 keyfob of PGST PG107 Alarm System 1.25.05.hf allows attackers to compromise access contro...
CVE-2025-69872CRITICAL9.8DiskCache (python-diskcache) through 5.6.3 uses Python pickle for serialization by default. An attacker with write acces...
CVE-2025-70085CRITICAL9.8An issue was discovered in OpenSatKit 2.2.1. The EventErrStr buffer has a fixed size of 256 bytes. The code uses sprintf...
CVE-2025-69874CRITICAL9.8nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers t...
CVE-2025-64075CRITICAL10A path traversal vulnerability in the check_token function of Shenzhen Zhibotong Electronics ZBT WE2001 23.09.27 allows ...
CVE-2025-12059CRITICAL9.8Insertion of Sensitive Information into Externally-Accessible File or Directory vulnerability in Logo Software Industry ...
CVE-2025-8668CRITICAL9.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite So...
CVE-2025-8025CRITICAL9.8Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinos...
CVE-2025-66277CRITICAL9.8A link following vulnerability has been reported to affect several QNAP operating system versions. The remote attackers ...
CVE-2025-7659CRITICAL9.1GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1...
CVE-2025-52436CRITICAL9.6An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-11242CRITICAL9.8Server-Side Request Forgery (SSRF) vulnerability in Teknolist Computer Systems Software Publishing Industry and Trade In...
CVE-2025-66630CRITICAL9.4Fiber is an Express inspired web framework written in Go. Before 2.52.11, on Go versions prior to 1.24, the underlying c...
CVE-2025-6830CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Info...
CVE-2025-66606CRITICAL9.6A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. This product does not properl...
CVE-2025-66603CRITICAL9.8A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts the OP...
CVE-2025-66602CRITICAL9.8A vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation. The web server accepts access...
CVE-2025-15027CRITICAL9.8The JAY Login & Register plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including...
CVE-2025-64111CRITICAL9.8Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-...
CVE-2025-68121CRITICAL10During session resumption in crypto/tls, if the underlying Config has its ClientCAs or RootCAs fields mutated between th...
CVE-2025-68723CRITICAL9Axigen Mail Server before 10.5.57 contains multiple stored Cross-Site Scripting (XSS) vulnerabilities in the WebAdmin in...
CVE-2025-62616CRITICAL9.8AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now