2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-64119CRITICAL9.3A vulnerability in Nuvation Battery Management System allows Authentication Bypass.This issue affects Battery Management...
CVE-2025-67268CRITICAL9.8gpsd before commit dc966aa contains a heap-based out-of-bounds write vulnerability in the drivers/driver_nmea2000.c file...
CVE-2025-59389CRITICAL9.8An SQL injection vulnerability has been reported to affect Hyper Data Protector. The remote attackers can then exploit t...
CVE-2025-11837CRITICAL9.8An improper control of generation of code vulnerability has been reported to affect Malware Remover. The remote attacker...
CVE-2025-65125CRITICAL9.8SQL injection in gosaliajainam/online-movie-booking 5.5 in movie_details.php allows attackers to gain sensitive informat...
CVE-2025-15436CRITICAL9.8A vulnerability has been found in Yonyou KSOA 9.0. Affected by this issue is some unknown functionality of the file /wor...
CVE-2025-15435CRITICAL9.8A flaw has been found in Yonyou KSOA 9.0. Affected by this vulnerability is an unknown functionality of the file /worksh...
CVE-2025-15434CRITICAL9.8A vulnerability was detected in Yonyou KSOA 9.0. Affected is an unknown function of the file /kp/PrintZPYG.jsp. The mani...
CVE-2025-15425CRITICAL9.8A vulnerability was determined in Yonyou KSOA 9.0. The impacted element is an unknown function of the file /worksheet/de...
CVE-2025-15424CRITICAL9.8A vulnerability was found in Yonyou KSOA 9.0. The affected element is an unknown function of the file /worksheet/agent_w...
CVE-2025-14998CRITICAL9.8The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in...
CVE-2025-15421CRITICAL9.8A vulnerability was detected in Yonyou KSOA 9.0. This vulnerability affects unknown code of the file /worksheet/agent_wo...
CVE-2025-15420CRITICAL9.8A security vulnerability has been detected in Yonyou KSOA 9.0. This affects an unknown part of the file /worksheet/agent...
CVE-2025-68620CRITICAL9.1Signal K Server is a server application that runs on a central hub in a boat. Versions prior to 2.19.0 expose two featur...
CVE-2025-15410CRITICAL9.8A vulnerability was identified in code-projects Online Guitar Store 1.0. Affected by this issue is some unknown function...
CVE-2025-15409CRITICAL9.8A vulnerability was determined in code-projects Online Guitar Store 1.0. Affected by this vulnerability is an unknown fu...
CVE-2025-15408CRITICAL9.8A vulnerability was found in code-projects Online Guitar Store 1.0. Affected is an unknown function of the file /admin/C...
CVE-2025-15407CRITICAL9.8A vulnerability has been found in code-projects Online Guitar Store 1.0. This impacts an unknown function of the file /a...
CVE-2025-69288CRITICAL9.1Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user...
CVE-2025-69286CRITICAL9.8RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecu...
CVE-2025-34468CRITICAL9.8libcoap versions up to and including 4.3.5, prior to commit 30db3ea, contain a stack-based buffer overflow in address re...
CVE-2025-15391CRITICAL9.8A weakness has been identified in D-Link DIR-806A 100CNb11. Affected is the function ssdpcgi_main of the component SSDP ...
CVE-2025-15114CRITICAL9.8Ksenia Security lares (legacy model) Home Automation version 1.6 contains a critical security flaw that exposes the alar...
CVE-2025-15113CRITICAL9.3Ksenia Security lares (legacy model) Home Automation version 1.6 contains an unprotected endpoint vulnerability that all...
CVE-2025-15111CRITICAL9.8Ksenia Security lares (legacy model) version 1.6 contains a default credentials vulnerability that allows unauthorized a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now