2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10656CRITICAL9.8The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Au...
CVE-2025-50455CRITICAL9.1SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp...
CVE-2025-71389CRITICAL10Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio...
CVE-2025-50329CRITICAL9.8An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec...
CVE-2025-66390CRITICAL9.8In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ...
CVE-2025-51677CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12...
CVE-2025-65720CRITICAL9.8An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user...
CVE-2025-11698CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit...
CVE-2025-12012CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u...
CVE-2025-12011CRITICAL9.2A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to ...
CVE-2025-58151CRITICAL9.4varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ...
CVE-2025-58146CRITICAL9.4There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica...
CVE-2025-27464CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27463CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27462CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-53830CRITICAL9.1Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud...
CVE-2025-53827CRITICAL9.1ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi...
CVE-2025-23351CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-23350CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-15646CRITICAL9.8HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w...
CVE-2025-11919CRITICAL9.6The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the...
CVE-2025-64152CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-55017CRITICAL9.1Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issu...
CVE-2025-71338CRITICAL9.8Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated at...
CVE-2025-71336CRITICAL9.8Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnera...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now