2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-37096CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37095CRITICAL9.8A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
CVE-2025-5447CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-37094CRITICAL9.1A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
CVE-2025-37093CRITICAL9.8An authentication bypass vulnerability exists in HPE StoreOnce Software.
CVE-2025-37092CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37091CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37090CRITICAL9.8A server-side request forgery vulnerability exists in HPE StoreOnce Software.
CVE-2025-37089CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-5446CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-5445CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-5444CRITICAL9.8A vulnerability has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.0...
CVE-2025-5443CRITICAL9.8A vulnerability, which was classified as critical, was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE900...
CVE-2025-5442CRITICAL9.8A vulnerability, which was classified as critical, has been found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and ...
CVE-2025-5441CRITICAL9.8A vulnerability classified as critical was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.00...
CVE-2025-47289CRITICAL9CE Phoenix is a free, open-source eCommerce platform. A stored cross-site scripting (XSS) vulnerability was discovered i...
CVE-2025-1750CRITICAL9.8An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12...
CVE-2025-5432CRITICAL9.8A vulnerability has been found in AssamLook CMS 1.0 and classified as critical. Affected by this vulnerability is an unk...
CVE-2025-5430CRITICAL9.8A vulnerability, which was classified as critical, has been found in AssamLook CMS 1.0. This issue affects some unknown ...
CVE-2025-20674CRITICAL9.8In wlan AP driver, there is a possible way to inject arbitrary packet due to a missing permission check. This could lead...
CVE-2025-20672CRITICAL9.8In Bluetooth driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local ...
CVE-2025-5409CRITICAL9.8A vulnerability was found in Mist Community Edition up to 4.7.1. It has been classified as critical. This affects the fu...
CVE-2025-5408CRITICAL9.8A vulnerability was found in WAVLINK QUANTUM D2G, QUANTUM D3G, WL-WN530G3A, WL-WN530HG3, WL-WN532A3 and WL-WN576K1 up to...
CVE-2025-5402CRITICAL9.8A vulnerability was found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. It has been rated as...
CVE-2025-40908CRITICAL9.1YAML-LibYAML prior to 0.903.0 for Perl uses 2-args open, allowing existing files to be modified

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now