2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-70968CRITICAL9.8FreeImage 3.18.0 contains a Use After Free in PluginTARGA.cpp;loadRLE().
CVE-2025-37184CRITICAL9.8A vulnerability exists in an Orchestrator service that could allow an unauthenticated remote attacker to bypass multi-fa...
CVE-2025-14502CRITICAL9.8The News and Blog Designer Bundle plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and ...
CVE-2025-14301CRITICAL9.8The Integration Opvius AI for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, an...
CVE-2025-37168CRITICAL9.1Arbitrary file deletion vulnerability have been identified in a system function of mobility conductors running AOS-8 ope...
CVE-2025-68271CRITICAL10OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2025-64155CRITICAL9.8An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet ...
CVE-2025-47855CRITICAL9.8An exposure of sensitive information to an unauthorized actor [CWE-200] vulnerability in Fortinet FortiFone 7.0.0 throug...
CVE-2025-25249CRITICAL9.8A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS...
CVE-2025-25176CRITICAL9.1Intermediate register values of secure workloads can be exfiltrated in workloads scheduled from applications running in ...
CVE-2025-69992CRITICAL9.8phpgurukul News Portal Project V4.1 has File Upload Vulnerability via upload.php, which enables the upload of files of a...
CVE-2025-69991CRITICAL9.8phpgurukul News Portal Project V4.1 is vulnerable to SQL Injection in check_availablity.php.
CVE-2025-69990CRITICAL9.1phpgurukul News Portal Project V4.1 has an Arbitrary File Deletion Vulnerability in remove_file.php. The parameter file ...
CVE-2025-68811CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: svcrdma: use rc_pageoff for memcpy byte offset svc...
CVE-2025-68809CRITICAL9.1In the Linux kernel, the following vulnerability has been resolved: ksmbd: vfs: fix race on m_flags in vfs_cache ksmbd...
CVE-2025-68794CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: iomap: adjust read range correctly for non-block-al...
CVE-2025-68775CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net/handshake: duplicate handshake cancellations le...
CVE-2025-65783CRITICAL9.8An arbitrary file upload vulnerability in the /utils/uploadFile component of Hubert Imoveis e Administracao Ltda Hub v2....
CVE-2025-12548CRITICAL9A flaw was found in Eclipse Che che-machine-exec. This vulnerability allows unauthenticated remote arbitrary command exe...
CVE-2025-11250CRITICAL9.1Zohocorp ManageEngine ADSelfService Plus versions before 6519 are vulnerable to Authentication Bypass due to improper fi...
CVE-2025-40805CRITICAL10Affected devices do not properly enforce user authentication on specific API endpoints. This could facilitate an unauthe...
CVE-2025-14829CRITICAL9.1The E-xact | Hosted Payment | WordPress plugin through 2.0 is vulnerable to arbitrary file deletion due to insufficient ...
CVE-2025-10915CRITICAL9.8The Dreamer Blog WordPress theme through 1.2 is vulnerable to arbitrary installations due to a missing capability check...
CVE-2025-67146CRITICAL9.4Multiple SQL Injection vulnerabilities exist in AbhishekMali21 GYM-MANAGEMENT-SYSTEM 1.0 via the 'name' parameter in (1)...
CVE-2025-29329CRITICAL9.8Buffer Overflow in the ippprint (Internet Printing Protocol) service in Sagemcom F@st 3686 MAGYAR_4.121.0 allows remote ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now