2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-31691CRITICAL9.8Missing Authorization vulnerability in Drupal OAuth2 Server allows Forceful Browsing.This issue affects OAuth2 Server: f...
CVE-2025-31685CRITICAL9.1Missing Authorization vulnerability in Drupal Open Social allows Forceful Browsing.This issue affects Open Social: from ...
CVE-2025-31681CRITICAL9.8Missing Authorization vulnerability in Drupal Authenticator Login allows Forceful Browsing.This issue affects Authentica...
CVE-2025-26683CRITICAL9.8Improper authorization in Azure Playwright allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-3006CRITICAL9.8A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been declared as critical. This vulnerabil...
CVE-2025-31122CRITICAL9scratch-coding-hut.github.io is the website for Coding Hut. In 1.0-beta3 and earlier, the login link can be used to logi...
CVE-2025-31116CRITICAL9.8Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of perfor...
CVE-2025-30223CRITICAL9.6Beego is an open-source web framework for the Go programming language. Prior to 2.3.6, a Cross-Site Scripting (XSS) vuln...
CVE-2025-30095CRITICAL9VyOS 1.3 through 1.5 (fixed in 1.4.2) or any Debian-based system using dropbear in combination with live-build has the s...
CVE-2025-22941CRITICAL9.8A command injection vulnerability in the web interface of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate pri...
CVE-2025-22940CRITICAL9.1Incorrect access control in Adtran 411 ONT L80.00.0011.M2 allows unauthorized attackers to arbitrarily set the admin pas...
CVE-2025-22939CRITICAL9.8A command injection vulnerability in the telnet service of Adtran 411 ONT L80.00.0011.M2 allows attackers to escalate pr...
CVE-2025-22938CRITICAL9.8Adtran 411 ONT L80.00.0011.M2 was discovered to contain weak default passwords.
CVE-2025-22937CRITICAL9.8An issue in Adtran 411 ONT vL80.00.0011.M2 allows attackers to escalate privileges via unspecified vectors.
CVE-2025-29266CRITICAL9.6Unraid 7.0.0 before 7.0.1 allows remote users to access the Unraid WebGUI and web console as root without authentication...
CVE-2025-3022CRITICAL9.3Os command injection vulnerability in e-solutions e-management. This vulnerability allows an attacker to execute arbitra...
CVE-2025-2071CRITICAL10A critical OS Command Injection vulnerability has been identified in the FAST LTA Silent Brick WebUI, allowing remote at...
CVE-2025-2978CRITICAL9.8A vulnerability was found in WCMS 11. It has been rated as critical. Affected by this issue is some unknown functionalit...
CVE-2025-26689CRITICAL9.8Direct request ('Forced Browsing') issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If a remote attacker...
CVE-2025-25211CRITICAL9.8Weak password requirements issue exists in CHOCO TEI WATCHER mini (IB-MCT001) all versions. If this issue is exploited, ...
CVE-2025-3011CRITICAL9.8SOOP-CLM from PiExtract has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary...
CVE-2025-2973CRITICAL9.8A vulnerability, which was classified as critical, was found in code-projects College Management System 1.0. This affect...
CVE-2025-1268CRITICAL9.4Out-of-bounds vulnerability in EMF Recode processing of Generic Plus PCL6 Printer Driver / Generic Plus UFR II Printer D...
CVE-2025-2952CRITICAL9.8A vulnerability classified as critical was found in Bluestar Micro Mall 1.0. Affected by this vulnerability is an unknow...
CVE-2025-2951CRITICAL9.8A vulnerability classified as critical has been found in Bluestar Micro Mall 1.0. Affected is an unknown function of the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now