2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-68741CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix improper freeing of purex item ...
CVE-2025-68726CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce1...
CVE-2025-68359CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of qgroup record after failu...
CVE-2025-13773CRITICAL9.8The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Remote Code Execution in all ve...
CVE-2025-68669CRITICAL9.65ire is a cross-platform desktop artificial intelligence assistant and model context protocol client. In versions 0.15.2...
CVE-2025-68667CRITICAL9.9Conduit is a chat server powered by Matrix. A vulnerability that affects a number of Conduit-derived homeservers allows ...
CVE-2025-68665CRITICAL9.1LangChain is a framework for building LLM-powered applications. Prior to @langchain/core versions 0.3.80 and 1.1.8, and ...
CVE-2025-15049CRITICAL9.8A vulnerability was identified in code-projects Online Farm System 1.0. Affected is an unknown function of the file /add...
CVE-2025-15048CRITICAL9.8A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools ...
CVE-2025-15047CRITICAL9.8A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of t...
CVE-2025-15046CRITICAL9.8A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/...
CVE-2025-14500CRITICAL9.8IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac...
CVE-2025-15045CRITICAL9.8A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit ...
CVE-2025-15044CRITICAL9.8A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetti...
CVE-2025-14931CRITICAL10Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. Th...
CVE-2025-65354CRITICAL9.8Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injecti...
CVE-2025-51511CRITICAL9.8Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.
CVE-2025-33224CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges....
CVE-2025-33223CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges....
CVE-2025-33222CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes...
CVE-2025-29229CRITICAL9.8linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
CVE-2025-29228CRITICAL9.8Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
CVE-2025-67109CRITICAL10Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica...
CVE-2025-67108CRITICAL10eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun...
CVE-2025-50526CRITICAL9.8Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now