2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15047 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of t... |
| CVE-2025-15046 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/... |
| CVE-2025-14500 | CRITICAL | 9.8 | 1.4% | Dec 23, 2025 | IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac... |
| CVE-2025-15045 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit ... |
| CVE-2025-15044 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetti... |
| CVE-2025-14931 | CRITICAL | 10 | 0.8% | Dec 23, 2025 | Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. Th... |
| CVE-2025-65354 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injecti... |
| CVE-2025-51511 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads. |
| CVE-2025-33224 | CRITICAL | 9.8 | 0.7% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33223 | CRITICAL | 9.8 | 0.6% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges.... |
| CVE-2025-33222 | CRITICAL | 9.8 | 0.5% | Dec 23, 2025 | NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes... |
| CVE-2025-29229 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus. |
| CVE-2025-29228 | CRITICAL | 9.8 | 1.1% | Dec 23, 2025 | Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter. |
| CVE-2025-67109 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica... |
| CVE-2025-67108 | CRITICAL | 10 | 0.3% | Dec 23, 2025 | eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun... |
| CVE-2025-50526 | CRITICAL | 9.8 | 1.0% | Dec 23, 2025 | Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function. |
| CVE-2025-68341 | CRITICAL | 9.8 | 0.2% | Dec 23, 2025 | In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix ra... |
| CVE-2025-14388 | CRITICAL | 9.8 | 0.4% | Dec 23, 2025 | The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all ... |
| CVE-2025-15034 | CRITICAL | 9.8 | 0.3% | Dec 23, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the f... |
| CVE-2025-68615 | CRITICAL | 9.8 | 42.7% | Dec 23, 2025 | net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted pac... |
| CVE-2025-65856 | CRITICAL | 9.8 | 0.7% | Dec 22, 2025 | Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.... |
| CVE-2025-67418 | CRITICAL | 9.8 | 0.6% | Dec 22, 2025 | ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded... |
| CVE-2025-67288 | CRITICAL | 10 | 0.5% | Dec 22, 2025 | An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a ... |
| CVE-2025-67289 | CRITICAL | 9.6 | 0.4% | Dec 22, 2025 | An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execut... |
| CVE-2025-11545 | CRITICAL | 9.5 | 0.3% | Dec 22, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now