2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-46274CRITICAL9.8UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to read, manipulate and create en...
CVE-2025-46273CRITICAL9.8UNI-NMS-Lite uses hard-coded credentials that could allow an unauthenticated attacker to gain administrative privileges...
CVE-2025-46272CRITICAL9.3WGS-80HPT-V2 and WGS-4215-8T2S are vulnerable to a command injection attack that could allow an unauthenticated attacke...
CVE-2025-46271CRITICAL9.3UNI-NMS-Lite is vulnerable to a command injection attack that could allow an unauthenticated attacker to read or manipu...
CVE-2025-26382CRITICAL9.3Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
CVE-2025-43859CRITICAL9.1h11 is a Python implementation of HTTP/1.1. Prior to version 0.16.0, a leniency in h11's parsing of line terminators in ...
CVE-2025-43858CRITICAL9.2YoutubeDLSharp is a wrapper for the command-line video downloaders youtube-dl and yt-dlp. In versions starting from 1.0....
CVE-2025-31324CRITICAL9.8SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated a...
CVE-2025-46264CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in blubrry PowerPress Podcasting powerpress allows Upload ...
CVE-2025-46248CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in M A Vinoth Kumar F...
CVE-2025-3604CRITICAL9.8The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-3603CRITICAL9.8The Flynax Bridge plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,...
CVE-2025-3065CRITICAL9.1The Database Toolset plugin is vulnerable to arbitrary file deletion due to insufficient file path validation in a funct...
CVE-2025-2767CRITICAL9.6Arista NG Firewall User-Agent Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote...
CVE-2025-45429CRITICAL9.8In the Tenda ac9 v1.0 router with firmware V15.03.05.14_multi, there is a stack overflow vulnerability in /goform/WifiWp...
CVE-2025-32969CRITICAL9.8XWiki is a generic wiki platform. In versions starting from 1.8 and prior to 15.10.16, 16.4.6, and 16.10.1, it is possib...
CVE-2025-32966CRITICAL9.8DataEase is an open-source BI tool alternative to Tableau. Prior to version 2.10.8, authenticated users can complete RCE...
CVE-2025-45428CRITICAL9.8In Tenda ac9 v1.0 with firmware V15.03.05.14_multi, the rebootTime parameter of /goform/SetSysAutoRebbotCfg has a stack ...
CVE-2025-45427CRITICAL9.8In Tenda AC9 v1.0 with firmware V15.03.05.14_multi, the security parameter of /goform/WifiBasicSet has a stack overflow ...
CVE-2025-42605CRITICAL9.3This vulnerability exists in Meon Bidding Solutions due to improper authorization controls on certain API endpoints for ...
CVE-2025-37087CRITICAL9.8A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access...
CVE-2025-32965CRITICAL9.3xrpl.js is a JavaScript/TypeScript API for interacting with the XRP Ledger in Node.js and the browser. Versions 4.2.1, 4...
CVE-2025-43951CRITICAL9.8LabVantage before LV 8.8.0.13 HF6 allows local file inclusion. Authenticated users can retrieve arbitrary files from the...
CVE-2025-43949CRITICAL9.8MuM (aka Mensch und Maschine) MapEdit (aka mapedit-web) 24.2.3 is vulnerable to SQL Injection that allows an attacker to...
CVE-2025-43946CRITICAL9.8TCPWave DDI 11.34P1C2 allows Remote Code Execution via Unrestricted File Upload (combined with Path Traversal).

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now