2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-15047CRITICAL9.8A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of t...
CVE-2025-15046CRITICAL9.8A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/...
CVE-2025-14500CRITICAL9.8IceWarp14 X-File-Operation Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attac...
CVE-2025-15045CRITICAL9.8A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit ...
CVE-2025-15044CRITICAL9.8A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetti...
CVE-2025-14931CRITICAL10Hugging Face smolagents Remote Python Executor Deserialization of Untrusted Data Remote Code Execution Vulnerability. Th...
CVE-2025-65354CRITICAL9.8Improper input handling in /Grocery/search_products_itname.php inPuneethReddyHC event-management 1.0 permits SQL injecti...
CVE-2025-51511CRITICAL9.8Cadmium CMS v.0.4.9 has a background arbitrary file upload vulnerability in /admin/content/filemanager/uploads.
CVE-2025-33224CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges....
CVE-2025-33223CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges....
CVE-2025-33222CRITICAL9.8NVIDIA Isaac Launchable contains a vulnerability where an attacker could exploit a hard-coded credential issue. A succes...
CVE-2025-29229CRITICAL9.8linksys E5600 V1.1.0.26 is vulnerable to command injection in the function ddnsStatus.
CVE-2025-29228CRITICAL9.8Linksys E5600 V1.1.0.26 is vulnerable to command injection in the runtime.macClone function via the mc.ip parameter.
CVE-2025-67109CRITICAL10Improper verification of the time certificate in Eclipse Cyclone DDS before v0.10.5 allows attackers to bypass certifica...
CVE-2025-67108CRITICAL10eProsima Fast-DDS v3.3 was discovered to contain improper validation for ticket revocation, resulting in insecure commun...
CVE-2025-50526CRITICAL9.8Netgear EX8000 V1.0.0.126 was discovered to contain a command injection vulnerability via the switch_status function.
CVE-2025-68341CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: veth: reduce XDP no_direct return section to fix ra...
CVE-2025-14388CRITICAL9.8The PhastPress plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Read via null byte injection in all ...
CVE-2025-15034CRITICAL9.8A security flaw has been discovered in itsourcecode Student Management System 1.0. This affects an unknown part of the f...
CVE-2025-68615CRITICAL9.8net-snmp is a SNMP application library, tools and daemon. Prior to versions 5.9.5 and 5.10.pre2, a specially crafted pac...
CVE-2025-65856CRITICAL9.8Authentication bypass vulnerability in Xiongmai XM530 IP cameras on Firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21....
CVE-2025-67418CRITICAL9.8ClipBucket 5.5.2 is affected by an improper access control issue where the product is shipped or deployed with hardcoded...
CVE-2025-67288CRITICAL10An arbitrary file upload vulnerability in Umbraco CMS v16.3.3 allows attackers to execute arbitrary code by uploading a ...
CVE-2025-67289CRITICAL9.6An arbitrary file upload vulnerability in the Attachments module of Frappe Framework v15.89.0 allows attackers to execut...
CVE-2025-11545CRITICAL9.5Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sharp Display Solutions proj...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now