2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-65826CRITICAL9.8The mobile application was found to contain stored credentials for the network it was developed on. If an attacker retri...
CVE-2025-65823CRITICAL9.8The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was d...
CVE-2025-65820CRITICAL9.8An issue was discovered in Meatmeet Android Mobile Application 1.1.2.0. An exported activity can be spawned with the mob...
CVE-2025-65602CRITICAL9.8A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbi...
CVE-2025-64539CRITICAL9.3Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64538CRITICAL9.3Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-64537CRITICAL9.3Adobe Experience Manager versions 6.5.23 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-13607CRITICAL9.4A malicious actor can access camera configuration information, including account credentials, without authenticating whe...
CVE-2025-65792CRITICAL9.1DataGear v5.5.0 is vulnerable to Arbitrary File Deletion.
CVE-2025-34394CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, exposes a .NET Remoting ser...
CVE-2025-34393CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not correctly verify t...
CVE-2025-34392CRITICAL9.8Barracuda Service Center, as implemented in the RMM solution, in versions prior to 2025.1.1, does not verify the URL def...
CVE-2025-13184CRITICAL9.8Unauthenticated Telnet enablement via cstecgi.cgi (auth bypass) leading to unauthenticated root login with a blank passw...
CVE-2025-13953CRITICAL9.3Bypass vulnerability in the authentication method in the GTT Tax Information System application, related to the Active D...
CVE-2025-41732CRITICAL9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_cookie() function to write arbitrary d...
CVE-2025-41730CRITICAL9.8An unauthenticated remote attacker can abuse unsafe sscanf calls within the check_account() function to write arbitrary ...
CVE-2025-14087CRITICAL9.8A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a...
CVE-2025-13955CRITICAL9.3Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows atta...
CVE-2025-13954CRITICAL9.3Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori...
CVE-2025-13613CRITICAL9.8The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, ...
CVE-2025-67506CRITICAL9.8PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0....
CVE-2025-61811CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-61809CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61808CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T...
CVE-2025-66039CRITICAL9.8FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to aut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now