2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-64691CRITICAL9.3The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scr...
CVE-2025-61937CRITICAL10The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS sys...
CVE-2025-14237CRITICAL9.8Buffer overflow in XPS font parse processing on Small Office Multifunction Printers and Laser Printers(*) which may allo...
CVE-2025-14236CRITICAL9.8Buffer overflow in Address Book attribute tag processing on Small Office Multifunction Printers(*) which may allow an at...
CVE-2025-14235CRITICAL9.8Buffer overflow in XPS font fpgm data processing on Small Office Multifunction Printers and Laser Printers(*) which may ...
CVE-2025-14234CRITICAL9.8Buffer overflow in CPCA list processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an ...
CVE-2025-14233CRITICAL9.8Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may all...
CVE-2025-14232CRITICAL9.8Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may all...
CVE-2025-14231CRITICAL9.8Buffer overflow in print job processing by WSD on Small Office Multifunction Printers and Laser Printers(*) which may al...
CVE-2025-67822CRITICAL9.4A vulnerability in the Provisioning Manager component of Mitel MiVoice MX-ONE 7.3 (7.3.0.0.50) through 7.8 SP1 (7.8.1.0....
CVE-2025-70892CRITICAL9.8Phpgurukul Cyber Cafe Management System v1.0 contains a SQL Injection vulnerability in the user management module. The a...
CVE-2025-67647CRITICAL9.1SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.49.5, Svelt...
CVE-2025-66417CRITICAL9.8GLPI is a free asset and IT management software package. From 11.0.0, < 11.0.3, an unauthenticated user can perform a SQ...
CVE-2025-62193CRITICAL9.8Sites running NOAA PMEL Live Access Server (LAS) are vulnerable to remote code execution via specially crafted requests ...
CVE-2025-67079CRITICAL9.8File upload vulnerability in Omnispace Agora Project before 25.10 allowing attackers to execute code through the MSL eng...
CVE-2025-67084CRITICAL9.9File upload vulnerability in InvoicePlane through 1.6.3 allows authenticated attackers to upload arbitrary PHP files int...
CVE-2025-70968CRITICAL9.8FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
CVE-2025-37184CRITICAL9.8A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-fa...
CVE-2025-14502CRITICAL9.8The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2025-14301CRITICAL9.8The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an...
CVE-2025-37168CRITICAL9.1Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope...
CVE-2025-68271CRITICAL10OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2025-64155CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2025-47855CRITICAL9.8An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 throug...
CVE-2025-25249CRITICAL9.8A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now