2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-6030CRITICAL9.4Use of fixed learning codes, one code to lock the car and the other code to unlock it, in the Key Fob Transmitter in Cyc...
CVE-2025-6029CRITICAL9.4Use of fixed learning codes, one code to lock the car and the other code to unlock it, the Key Fob Transmitter in KIA-br...
CVE-2025-28389CRITICAL9.8Weak password requirements in OpenC3 COSMOS v6.0.0 allow attackers to bypass authentication via a brute force attack.
CVE-2025-28388CRITICAL9.8OpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.
CVE-2025-28386CRITICAL9.8A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers ...
CVE-2025-28384CRITICAL9.1An issue in the /script-api/scripts/ endpoint of OpenC3 COSMOS before 6.1.0 allows attackers to execute a directory trav...
CVE-2025-46060CRITICAL9.8Buffer Overflow vulnerability in TOTOLINK N600R v4.3.0cu.7866_B2022506 allows a remote attacker to execute arbitrary cod...
CVE-2025-45988CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45987CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45986CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45985CRITICAL9.8Blink routers BL-WR9000 V2.4.9 , BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 v1.0.5 , BL-LTE300 v1.2.3, BL-F1200_AT1 v1.0.0, BL-X26...
CVE-2025-45984CRITICAL9.8Blink routers BL-WR9000 V2.4.9, BL-AC1900 V1.0.2, BL-AC2100_AZ3 V1.0.4, BL-X10_AC8 V1.0.5, BL-LTE300 V1.2.3, BL-F1200_AT...
CVE-2025-29902CRITICAL10Remote code execution that allows unauthorized users to execute arbitrary code on the server machine.
CVE-2025-46783CRITICAL9.8Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability...
CVE-2025-5288CRITICAL9.8The REST API | Custom API Generator For Cross Platform And Import Export In WP plugin for WordPress is vulnerable to Pri...
CVE-2025-43863CRITICAL9.8vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Le...
CVE-2025-49467CRITICAL9.3A SQL injection vulnerability in JEvents component before 3.6.88 and 3.6.82.1 for Joomla was discovered. The extension i...
CVE-2025-49199CRITICAL9.8The backup ZIPs are not signed by the application, leading to the possibility that an attacker can download a backup ZIP...
CVE-2025-49196CRITICAL9.1A service supports the use of a deprecated and unsafe TLS version. This could be exploited to expose sensitive informati...
CVE-2025-49195CRITICAL9.8The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user pas...
CVE-2025-49182CRITICAL9.8Files in the source code contain login credentials for the admin user and the property configuration password, allowing ...
CVE-2025-4973CRITICAL9.8The Workreap plugin for WordPress, used by the Workreap - Freelance Marketplace WordPress Theme, is vulnerable to authen...
CVE-2025-30085CRITICAL9.2Remote code execution vulnerability in RSForm!pro component 3.0.0 - 3.3.14 for Joomla was discovered. The issue occurs w...
CVE-2025-40912CRITICAL9.8CryptX for Perl before version 0.065 contains a dependency that may be susceptible to malformed unicode. CryptX embeds ...
CVE-2025-40914CRITICAL9.8Perl CryptX before version 0.087 contains a dependency that may be susceptible to an integer overflow. CryptX embeds a ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now