2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-46673CRITICAL9.9NASA CryptoLib before 1.3.2 does not check whether the SA is in an operational state before use, possibly leading to a b...
CVE-2025-2907CRITICAL9.8The Order Delivery Date WordPress plugin before 12.3.1 does not have authorization and CSRF checks when importing settin...
CVE-2025-32985CRITICAL9.8NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.
CVE-2025-32980CRITICAL9.8NETSCOUT nGeniusONE before 6.4.0 P11 b3245 has a Weak Sudo Configuration.
CVE-2025-25775CRITICAL9.8Codeastro Bus Ticket Booking System v1.0 is vulnerable to SQL injection via the kodetiket parameter in /BusTicket-CI/tik...
CVE-2025-46433CRITICAL9.8In JetBrains TeamCity before 2025.03.1 improper path validation in loggingPreset parameter was possible
CVE-2025-32432CRITICAL10Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from vers...
CVE-2025-2470CRITICAL9.8The Service Finder Bookings plugin for WordPress, used by the Service Finder - Directory and Job Board WordPress Theme, ...
CVE-2025-46616CRITICAL9.9Quantum StorNext Web GUI API before 7.2.4 allows potential Arbitrary Remote Code Execution (RCE) via upload of a file. T...
CVE-2025-46275CRITICAL9.8WGS-80HPT-V2 and WGS-4215-8T2S are missing authentication that could allow an attacker to create an administrator accou...
CVE-2025-46274CRITICAL9.8UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create en...
CVE-2025-46273CRITICAL9.8UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges...
CVE-2025-46272CRITICAL9.3WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke...
CVE-2025-46271CRITICAL9.3UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu...
CVE-2025-26382CRITICAL9.3Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
CVE-2025-43859CRITICAL9.1h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in ...
CVE-2025-43858CRITICAL9.2YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0....
CVE-2025-31324CRITICAL9.8SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated a...
CVE-2025-46264CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload ...
CVE-2025-46248CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar F...
CVE-2025-3604CRITICAL9.8The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-3603CRITICAL9.8The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-3065CRITICAL9.1The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct...
CVE-2025-2767CRITICAL9.6Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2025-45429CRITICAL9.8In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now