2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-2322CRITICAL9.8A vulnerability was found in 274056675 springboot-openai-chatgpt e84f6f5. It has been classified as critical. This affec...
CVE-2025-1771CRITICAL9.8The Traveler theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.8 via t...
CVE-2025-2320CRITICAL9.8A vulnerability has been found in 274056675 springboot-openai-chatgpt e84f6f5 and classified as critical. Affected by th...
CVE-2025-29775CRITICAL9.3xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab...
CVE-2025-29774CRITICAL9.3xml-crypto is an XML digital signature and encryption library for Node.js. An attacker may be able to exploit a vulnerab...
CVE-2025-29386CRITICAL9.8In Tenda AC9 v1.0 V15.03.05.14_multi, the mac parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability, w...
CVE-2025-29385CRITICAL9.8In Tenda AC9 v1.0 V15.03.05.14_multi, the cloneType parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerabil...
CVE-2025-29384CRITICAL9.8In Tenda AC9 v1.0 V15.03.05.14_multi, the wanMTU parameter of /goform/AdvSetMacMtuWan has a stack overflow vulnerability...
CVE-2025-29031CRITICAL9.8Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.
CVE-2025-29030CRITICAL9.8Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.
CVE-2025-29029CRITICAL9.8Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.
CVE-2025-2304CRITICAL9.4A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the ...
CVE-2025-2000CRITICAL9.8A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation...
CVE-2025-27595CRITICAL9.8The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculat...
CVE-2025-27593CRITICAL9.3The product can be used to distribute malicious code using SDD Device Drivers due to missing download verification check...
CVE-2025-2232CRITICAL9.8The Realteo - Real Estate Plugin by Purethemes plugin for WordPress, used by the Findeo Theme, is vulnerable to authenti...
CVE-2025-26163CRITICAL9.8CM Soluces Informatica Ltda Auto Atendimento 1.x.x was discovered to contain a SQL injection via the CPF parameter.
CVE-2025-2263CRITICAL9.8During login to the web server in "Sante PACS Server.exe", OpenSSL function EVP_DecryptUpdate is called to decrypt the u...
CVE-2025-2080CRITICAL9.3Optigo Networks Visual BACnet Capture Tool and Optigo Visual Networks Capture Tool version 3.1.2rc11 contain an exposed ...
CVE-2025-27138CRITICAL9.8DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.6, there is a flaw i...
CVE-2025-25292CRITICAL9.8ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vul...
CVE-2025-25291CRITICAL9.8ruby-saml provides security assertion markup language (SAML) single sign-on (SSO) for Ruby. An authentication bypass vul...
CVE-2025-27407CRITICAL9graphql-ruby is a Ruby implementation of GraphQL. Starting in version 1.11.5 and prior to versions 1.11.8, 1.12.25, 1.13...
CVE-2025-25568CRITICAL9.8SoftEtherVPN 5.02.5187 is vulnerable to Use after Free in the Command.c file via the CheckNetworkAcceptThread function. ...
CVE-2025-25567CRITICAL9.8SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in Internat.c via the UniToStrForSingleChars function. NOTE: th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now