2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27593CRITICAL9.3The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification check...
CVE-2025-2232CRITICAL9.8The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authenti...
CVE-2025-26163CRITICAL9.8CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.
CVE-2025-2263CRITICAL9.8During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the u...
CVE-2025-2080CRITICAL9.3Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed ...
CVE-2025-27138CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw i...
CVE-2025-25292CRITICAL9.8ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vul...
CVE-2025-25291CRITICAL9.8ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vul...
CVE-2025-27407CRITICAL9graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13...
CVE-2025-25568CRITICAL9.8SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. ...
CVE-2025-25567CRITICAL9.8SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: th...
CVE-2025-25565CRITICAL9.8SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 fun...
CVE-2025-1960CRITICAL9.8CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to exe...
CVE-2025-22954CRITICAL10GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi...
CVE-2025-2219CRITICAL9.8A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unkno...
CVE-2025-2218CRITICAL9.8A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affec...
CVE-2025-2217CRITICAL9.8A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This ...
CVE-2025-2216CRITICAL9.8A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. ...
CVE-2025-28915CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Uplo...
CVE-2025-28872CRITICAL9.8Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing...
CVE-2025-23360CRITICAL9.8NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary fil...
CVE-2025-23243CRITICAL9.1NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of ...
CVE-2025-23242CRITICAL9.8NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of ...
CVE-2025-26701CRITICAL10An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead...
CVE-2025-24201CRITICAL10An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now