2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32106CRITICAL9.8In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated re...
CVE-2025-32105CRITICAL9.8A buffer overflow in the the Sangoma IMG2020 HTTP server through 2.3.9.6 allows an unauthenticated user to achieve remot...
CVE-2025-5509CRITICAL9.8A vulnerability classified as critical has been found in quequnlong shiyi-blog up to 1.2.1. This affects an unknown part...
CVE-2025-45854CRITICAL10/server/executeExec of JEHC-BPM 2.0.1 allows attackers to execute arbitrary code via execParams.
CVE-2025-44148CRITICAL9.8Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via...
CVE-2025-5502CRITICAL9.8A vulnerability, which was classified as critical, has been found in TOTOLINK X15 1.0.0-B20230714.1105. Affected by this...
CVE-2025-5499CRITICAL9.8A vulnerability classified as critical has been found in slackero phpwcms up to 1.9.45/1.10.8. Affected is the function ...
CVE-2025-5497CRITICAL9.8A vulnerability was detected in slackero phpwcms up to 1.9.45/1.10.8. The impacted element is an unknown function of the...
CVE-2025-5495CRITICAL9.8A vulnerability was found in Netgear WNR614 1.1.0.28_1.0.1WW. It has been classified as critical. This affects an unknow...
CVE-2025-4517CRITICAL9.4Allows arbitrary filesystem writes outside the extraction directory during extraction with filter="data". You are affe...
CVE-2025-5493CRITICAL9.8A vulnerability was found in Baison Channel Middleware Product 2.0.1 and classified as critical. Affected by this issue ...
CVE-2025-4797CRITICAL9.8The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeo...
CVE-2025-23099CRITICAL9.1An issue was discovered in Samsung Mobile Processor Exynos 1480 and 2400. The lack of a length check leads to out-of-bou...
CVE-2025-5086CRITICAL9A deserialization of untrusted data vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could l...
CVE-2025-37096CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37095CRITICAL9.8A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
CVE-2025-5447CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-37094CRITICAL9.1A directory traversal arbitrary file deletion vulnerability exists in HPE StoreOnce Software.
CVE-2025-37093CRITICAL9.8An authentication bypass vulnerability exists in HPE StoreOnce Software.
CVE-2025-37092CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37091CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-37090CRITICAL9.8A server-side request forgery vulnerability exists in HPE StoreOnce Software.
CVE-2025-37089CRITICAL9.8A command injection remote code execution vulnerability exists in HPE StoreOnce Software.
CVE-2025-5446CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...
CVE-2025-5445CRITICAL9.8A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now