2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-61492CRITICAL10A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to e...
CVE-2025-12543CRITICAL9.6A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The...
CVE-2025-47552CRITICAL9.8Deserialization of Untrusted Data vulnerability in Digital zoom studio DZS Video Gallery allows Object Injection.This is...
CVE-2025-32303CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH ...
CVE-2025-68637CRITICAL9.1The Uniffle HTTP client is configured to trust all SSL certificates and disables hostname verification by default. This...
CVE-2025-15018CRITICAL9.8The Optional Email plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to...
CVE-2025-15471CRITICAL9.8A vulnerability was detected in TRENDnet TEW-713RE 1.02. The impacted element is an unknown function of the file /goform...
CVE-2025-30996CRITICAL9.9Unrestricted Upload of File with Dangerous Type vulnerability in Themify Themify Sidepane WordPress Theme, Themify Themi...
CVE-2025-14942CRITICAL9.8wolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to ...
CVE-2025-60534CRITICAL9.8Blue Access Cobalt v02.000.195 suffers from an authentication bypass vulnerability, which allows an attacker to selectiv...
CVE-2025-39477CRITICAL9.8Missing Authorization vulnerability in Sfwebservice InWave Jobs allows Exploiting Incorrectly Configured Access Control ...
CVE-2025-65212CRITICAL9.8An issue was discovered in NJHYST HY511 POE core before 2.1 and plugins before 0.1. The vulnerability stems from the dev...
CVE-2025-60262CRITICAL9.8An issue in H3C M102G HM1A0V200R010 wireless controller and BA1500L SWBA1A0V100R006 wireless access point, there is a mi...
CVE-2025-15001CRITICAL9.8The FS Registration Password plugin for WordPress is vulnerable to privilege escalation via account takeover in all vers...
CVE-2025-14996CRITICAL9.8The AS Password Field In Default Registration Form plugin for WordPress is vulnerable to privilege escalation via accoun...
CVE-2025-15385CRITICAL9.8Insufficient Verification of Data Authenticity vulnerability in TECNO Mobile com.Afmobi.Boomplayer allows Authentication...
CVE-2025-15444CRITICAL9.8Crypt::Sodium::XS module versions prior to 0.000042, for Perl, include a vulnerable version of libsodium libsodium <= 1...
CVE-2025-68456CRITICAL9.1Craft is a platform for creating digital experiences. In versions 5.0.0-RC1 through 5.8.20 and 3.0.0 through 4.16.16, u...
CVE-2025-65110CRITICAL9.3Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design...
CVE-2025-67397CRITICAL9.1An issue in Passy v.1.6.3 allows a remote authenticated attacker to execute arbitrary commands via a crafted HTTP reques...
CVE-2025-27807CRITICAL9.1An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-61781CRITICAL9.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6....
CVE-2025-55204CRITICAL9.6muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Exec...
CVE-2025-59467CRITICAL9.6A Cross-Site Scripting (XSS) vulnerability in the UCRM Argentina AFIP invoices Plugin (v1.2.0 and earlier) could allow p...
CVE-2025-39484CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada all...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now