2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-25675CRITICAL9.8Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str vari...
CVE-2025-25674CRITICAL9.8Tenda AC10 V1.0 V15.03.06.23 is vulnerable to Buffer Overflow in form_fast_setting_wifi_set via the parameter ssid.
CVE-2025-25668CRITICAL9.8Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_47D878 funct...
CVE-2025-25667CRITICAL9.8Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the urls parameter in the function get_parentCon...
CVE-2025-25664CRITICAL9.8Tenda AC8V4 V16.03.34.06 was discovered to contain a stack overflow via the shareSpeed parameter in the sub_49E098 funct...
CVE-2025-25663CRITICAL9.8A vulnerability was found in Tenda AC8V4 V16.03.34.06. Affected is the function SUB_0046AC38 of the file /goform/WifiExt...
CVE-2025-25662CRITICAL9.8Tenda O4 V3.0 V1.0.0.10(2936) is vulnerable to Buffer Overflow in the function SafeSetMacFilter of the file /goform/setM...
CVE-2025-24893CRITICAL9.8XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can p...
CVE-2025-1265CRITICAL9.9An OS command injection vulnerability exists in Vinci Protocol Analyzer that could allow an attacker to escalate privile...
CVE-2025-27096CRITICAL9.8WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovere...
CVE-2025-20059CRITICAL9.2Relative Path Traversal vulnerability in Ping Identity PingAM Java Policy Agent allows Parameter Injection.This issue af...
CVE-2025-0868CRITICAL9.3A vulnerability, that could result in Remote Code Execution (RCE), has been found in DocsGPT. Due to improper parsing of...
CVE-2025-24989CRITICAL9.8An improper access control vulnerability in Power Pages allows an unauthorized attacker to elevate privileges over a net...
CVE-2025-21355CRITICAL9.8Missing Authentication for Critical Function in Microsoft Bing allows an unauthorized attacker to execute code over a ne...
CVE-2025-25196CRITICAL9.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-25467CRITICAL9.8Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary...
CVE-2025-26617CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26613CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection ...
CVE-2025-26612CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26611CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26610CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26609CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26608CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26607CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26606CRITICAL9.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now