2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32969CRITICAL9.8XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possib...
CVE-2025-32966CRITICAL9.8DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE...
CVE-2025-45428CRITICAL9.8In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack ...
CVE-2025-45427CRITICAL9.8In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow ...
CVE-2025-42605CRITICAL9.3This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for ...
CVE-2025-37087CRITICAL9.8A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access...
CVE-2025-32965CRITICAL9.3xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4...
CVE-2025-43951CRITICAL9.8LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the...
CVE-2025-43949CRITICAL9.8MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to...
CVE-2025-43946CRITICAL9.8TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).
CVE-2025-28039CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s...
CVE-2025-28038CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s...
CVE-2025-28036CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se...
CVE-2025-28035CRITICAL9.8TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set...
CVE-2025-34028CRITICAL10The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta...
CVE-2025-28037CRITICAL9.8TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman...
CVE-2025-28024CRITICAL9.8TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi
CVE-2025-23251CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by rem...
CVE-2025-23250CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a r...
CVE-2025-23249CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote co...
CVE-2025-28034CRITICAL9.8TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51...
CVE-2025-3472CRITICAL9.8The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...
CVE-2025-46247CRITICAL9.8Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Acces...
CVE-2025-46244CRITICAL9.8Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Explo...
CVE-2025-3856CRITICAL9.8A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now