2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25565CRITICAL9.8SoftEther VPN 5.02.5187 is vulnerable to Buffer Overflow in the Command.c file via the PtMakeCert and PtMakeCert2048 fun...
CVE-2025-1960CRITICAL9.8CWE-1188: Initialization of a Resource with an Insecure Default vulnerability exists that could cause an attacker to exe...
CVE-2025-22954CRITICAL10GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi...
CVE-2025-2219CRITICAL9.8A vulnerability was found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This issue affects some unkno...
CVE-2025-2218CRITICAL9.8A vulnerability has been found in LoveCards LoveCardsV2 up to 2.3.2 and classified as critical. This vulnerability affec...
CVE-2025-2217CRITICAL9.8A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This ...
CVE-2025-2216CRITICAL9.8A vulnerability, which was classified as critical, has been found in zzskzy Warehouse Refinement Management System 1.3. ...
CVE-2025-28915CRITICAL9.1Unrestricted Upload of File with Dangerous Type vulnerability in Theme Egg ThemeEgg ToolKit themeegg-toolkit allows Uplo...
CVE-2025-28872CRITICAL9.8Missing Authorization vulnerability in jwpegram Block Spam By Math Reloaded block-spam-by-math-reloaded allows Accessing...
CVE-2025-23360CRITICAL9.8NVIDIA Nemo Framework contains a vulnerability where a user could cause a relative path traversal issue by arbitrary fil...
CVE-2025-23243CRITICAL9.1NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of ...
CVE-2025-23242CRITICAL9.8NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of ...
CVE-2025-26701CRITICAL10An issue was discovered in Percona PMM Server (OVA) before 3.0.0-1.ova. The default service account credentials can lead...
CVE-2025-24201CRITICAL10An out-of-bounds write issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in ...
CVE-2025-1550CRITICAL9.8The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually const...
CVE-2025-1661CRITICAL9.8The HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in a...
CVE-2025-27925CRITICAL9.8Nintex Automation 5.6 and 5.7 before 5.8 has insecure deserialization of user input.
CVE-2025-25306CRITICAL9.3Misskey is an open source, federated social media platform. The patch for CVE-2024-52591 did not sufficiently validate t...
CVE-2025-24813CRITICAL9.8Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malic...
CVE-2025-25977CRITICAL9.8An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code via the Constructor of the class StyleElement.
CVE-2025-25940CRITICAL9.8VisiCut 2.1 allows code execution via Insecure XML Deserialization in the loadPlfFile method of VisicutModel.java.
CVE-2025-26936CRITICAL10Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework all...
CVE-2025-26916CRITICAL9Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-2152CRITICAL9.8A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue ...
CVE-2025-1497CRITICAL9.8A vulnerability, that could result in Remote Code Execution (RCE), has been found in PlotAI. Lack of validation of LLM-g...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now