2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-43564CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-43563CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-43562CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements ...
CVE-2025-43561CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2025-43560CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-43559CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-45863CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMa...
CVE-2025-45865CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formD...
CVE-2025-45861CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the fo...
CVE-2025-45746CRITICAL9.8In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authentica...
CVE-2025-4660CRITICAL9.8A remote code execution vulnerability exists in the Windows agent component of SecureConnector due to improper access co...
CVE-2025-4658CRITICAL9.8Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by...
CVE-2025-3757CRITICAL9.8Versions of OpenPubkey library prior to 0.10.0 contained a vulnerability that would allow a specially crafted JWS to by...
CVE-2025-30387CRITICAL9.8Improper limitation of a pathname to a restricted directory ('path traversal') in Azure allows an unauthorized attacker ...
CVE-2025-45858CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability via the FUN_00459fdc f...
CVE-2025-45857CRITICAL9.8EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in...
CVE-2025-31493CRITICAL9.1Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff...
CVE-2025-28056CRITICAL9.8rebuild v3.9.0 through v3.9.3 has a SQL injection vulnerability in /admin/admin-cli/exec component.
CVE-2025-22462CRITICAL9.8An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Se...
CVE-2025-44831CRITICAL9.8EngineerCMS v1.02 through v2.0.5 has a SQL injection vulnerability in the /project/addproject interface.
CVE-2025-32756CRITICAL9.8A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCa...
CVE-2025-30159CRITICAL9.1Kirby is an open-source content management system. A vulnerability in versions prior to 3.9.8.3, 3.10.1.2, and 4.7.1 aff...
CVE-2025-40628CRITICAL9.3SQL injection vulnerability in DomainsPRO 1.2. This vulnerability could allow an attacker to retrieve, create, update an...
CVE-2025-40566CRITICAL9.8A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All ve...
CVE-2025-33025CRITICAL9.9A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.16.5), RUGGEDCOM ROX MX5000RE (All versio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now