2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-32434CRITICAL9.8PyTorch is a Python package that provides tensor computation with strong GPU acceleration and deep neural networks built...
CVE-2025-29953CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache ActiveMQ NMS OpenWire Client. This issue affects Apache Activ...
CVE-2025-29209CRITICAL9.8TOTOLINK X18 v9.1.0cu.2024_B20220329 has an unauthorized arbitrary command execution in the enable parameter' of the sub...
CVE-2025-28232CRITICAL9.1Incorrect access control in the HOME.php endpoint of JMBroadcast JMB0150 Firmware v1.0 allows attackers to access the Ad...
CVE-2025-28230CRITICAL9.1Incorrect access control in JMBroadcast JMB0150 Firmware v1.0 allows attackers to access hardcoded administrator credent...
CVE-2025-28229CRITICAL9.8Incorrect access control in Orban OPTIMOD 5950 Firmware v1.0.0.2 and System v2.2.15 allows attackers to bypass authentic...
CVE-2025-2492CRITICAL9.2An improper authentication control vulnerability exists in AiCloud. This vulnerability can be triggered by a crafted req...
CVE-2025-3783CRITICAL9.8A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Aff...
CVE-2025-1863CRITICAL9.8Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default se...
CVE-2025-39471CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pantherius Modal S...
CVE-2025-42599CRITICAL9.8Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a sp...
CVE-2025-3762CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-28009CRITICAL9.8A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.2...
CVE-2025-2947CRITICAL9.8IBM i 7.6  contains a privilege escalation vulnerability due to incorrect profile swapping in an OS command.  A malicio...
CVE-2025-29662CRITICAL9.8A RCE vulnerability in the core application in LandChat 3.25.12.18 allows an unauthenticated attacker to execute system ...
CVE-2025-43012CRITICAL9.8In JetBrains Toolbox App before 2.6 command injection in SSH plugin was possible
CVE-2025-39596CRITICAL9.8Weak Authentication vulnerability in Quentn.com GmbH Quentn WP quentn-wp allows Privilege Escalation.This issue affects ...
CVE-2025-39595CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Quentn.com GmbH Qu...
CVE-2025-39588CRITICAL9.8Deserialization of Untrusted Data vulnerability in bdthemes Ultimate Store Kit Elementor Addons ultimate-store-kit allow...
CVE-2025-39587CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Stylemix Cost Calc...
CVE-2025-39551CRITICAL9.8Deserialization of Untrusted Data vulnerability in Mahmudul Hasan Arif FluentBoards fluent-boards allows Object Injectio...
CVE-2025-39550CRITICAL9.8Deserialization of Untrusted Data vulnerability in Shahjahan Jewel FluentCommunity fluent-community allows Object Inject...
CVE-2025-39436CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in aidraw I Draw idraw allows Using Malicious Files.This i...
CVE-2025-32682CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg-lite-interactive-vector-maps al...
CVE-2025-32665CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WebbyTemplate Offi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now