2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-28039CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s...
CVE-2025-28038CRITICAL9.8TOTOLINK EX1200T V4.1.2cu.5232_B20210713 was found to contain a pre-auth remote command execution vulnerability in the s...
CVE-2025-28036CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the se...
CVE-2025-28035CRITICAL9.8TOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the set...
CVE-2025-34028CRITICAL10The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent insta...
CVE-2025-28037CRITICAL9.8TOTOLINK A810R V4.1.2cu.5182_B20201026 and A950RG V4.1.2cu.5161_B20200903 were found to contain a pre-auth remote comman...
CVE-2025-28024CRITICAL9.8TOTOLINK A810R V4.1.2cu.5182_B20201026 was found to contain a buffer overflow vulnerability in the cstecgi.cgi
CVE-2025-23251CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by rem...
CVE-2025-23250CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a r...
CVE-2025-23249CRITICAL9.8NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote co...
CVE-2025-28034CRITICAL9.8TOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.51...
CVE-2025-3472CRITICAL9.8The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including...
CVE-2025-46247CRITICAL9.8Missing Authorization vulnerability in codepeople Appointment Booking Calendar appointment-booking-calendar allows Acces...
CVE-2025-46244CRITICAL9.8Missing Authorization vulnerability in Dotstore Advanced Linked Variations for Woocommerce linked-variation allows Explo...
CVE-2025-3856CRITICAL9.8A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been classified as critical. This affects the function sea...
CVE-2025-3847CRITICAL9.8A vulnerability classified as critical has been found in markparticle WebServer up to 1.0. This affects an unknown part ...
CVE-2025-3846CRITICAL9.8A vulnerability was found in markparticle WebServer up to 1.0. It has been rated as critical. Affected by this issue is ...
CVE-2025-3845CRITICAL9.8A vulnerability was found in markparticle WebServer up to 1.0. It has been declared as critical. Affected by this vulner...
CVE-2025-3842CRITICAL9.8A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUse...
CVE-2025-32958CRITICAL9.8Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses act...
CVE-2025-3841CRITICAL9.8A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f9...
CVE-2025-28104CRITICAL9.1Incorrect access control in laskBlog v2.6.1 allows attackers to access all usernames via a crafted input.
CVE-2025-32431CRITICAL9.1Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-...
CVE-2025-29660CRITICAL9.8A vulnerability exists in the daemon process of the Yi IOT XY-3820 v6.0.24.10, which exposes a TCP service on port 6789....
CVE-2025-29659CRITICAL9.8Yi IOT XY-3820 6.0.24.10 is vulnerable to Remote Command Execution via the "cmd_listen" function located in the "cmd" bi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now