2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32002CRITICAL9.8Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in I-O DATA netw...
CVE-2025-3917CRITICAL9.8The 百度站长SEO合集(支持百度/神马/Bing/头条推送) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type v...
CVE-2025-47889CRITICAL9.8In Jenkins WSO2 Oauth Plugin 1.0 and earlier, authentication claims are accepted without validation by the "WSO2 Oauth" ...
CVE-2025-47884CRITICAL9.1In Jenkins OpenID Connect Provider Plugin 96.vee8ed882ec4d and earlier the generation of build ID Tokens uses potentiall...
CVE-2025-27891CRITICAL9.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-32363CRITICAL9.8mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization...
CVE-2025-4641CRITICAL9.3Improper Restriction of XML External Entity Reference vulnerability in bonigarcia webdrivermanager WebDriverManager on W...
CVE-2025-4638CRITICAL9.8A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (P...
CVE-2025-47781CRITICAL9.8Rallly is an open-source scheduling and collaboration tool. Versions up to and including 3.22.1 of the application featu...
CVE-2025-47777CRITICAL9.65ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. Versions prior to ...
CVE-2025-47436CRITICAL9.8Heap-based Buffer Overflow vulnerability in Apache ORC. A vulnerability has been identified in the ORC C++ LZO decompre...
CVE-2025-47445CRITICAL9.8Relative Path Traversal vulnerability in Arraytics Eventin wp-event-solution allows Path Traversal.This issue affects Ev...
CVE-2025-47292CRITICAL9.5Cap Collectif is an online decision making platform that integrates several tools. Before commit 812f2a7d271b76deab1175b...
CVE-2025-3623CRITICAL9.1The Uncanny Automator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 6...
CVE-2025-43567CRITICAL9.3Adobe Connect versions 12.8 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability that could ...
CVE-2025-43564CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-43563CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-43562CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements ...
CVE-2025-43561CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Incorrect Authorization vulnerability that c...
CVE-2025-43560CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-43559CRITICAL9.1ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-45863CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the macstr parameter in the formMa...
CVE-2025-45865CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the dnsaddr parameter in the formD...
CVE-2025-45861CRITICAL9.8TOTOLINK A3002R v4.0.0-B20230531.1404 was discovered to contain a buffer overflow via the routername parameter in the fo...
CVE-2025-45746CRITICAL9.8In ZKT ZKBio CVSecurity 6.4.1_R an unauthenticated attacker can craft JWT token using the hardcoded secret to authentica...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now