2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-14087CRITICAL9.8A flaw was found in GLib (Gnome Lib). This vulnerability allows a remote attacker to cause heap corruption, leading to a...
CVE-2025-13955CRITICAL9.3Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows atta...
CVE-2025-13954CRITICAL9.3Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori...
CVE-2025-13613CRITICAL9.8The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, ...
CVE-2025-67506CRITICAL9.8PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0....
CVE-2025-61811CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Access Control vulnerability that c...
CVE-2025-61809CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Improper Input Validation vulnerability that...
CVE-2025-61808CRITICAL9.1ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier are affected by an Unrestricted Upload of File with Dangerous T...
CVE-2025-66039CRITICAL9.8FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to aut...
CVE-2025-67489CRITICAL9.8@vitejs/plugin-rs provides React Server Components (RSC) support for Vite. Versions 0.5.5 and below are vulnerable to ar...
CVE-2025-66456CRITICAL9.8Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation and client-server communi...
CVE-2025-65741CRITICAL9.8Sublime Text 3 Build 3208 or prior for MacOS is vulnerable to Dylib Injection. An attacker could compile a .dylib file a...
CVE-2025-64113CRITICAL9.8Emby Server is a user-installable home media server. Versions below 4.9.1.81 allow an attacker to gain full administrati...
CVE-2025-14337CRITICAL9.8A vulnerability was determined in itsourcecode Student Management System 1.0. This affects an unknown part of the file /...
CVE-2025-65882CRITICAL9.8An issue was discovered in openmptcprouter thru 0.64 in file common/package/utils/sys-upgrade-helper/src/tools/sysupgrad...
CVE-2025-14336CRITICAL9.8A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown function...
CVE-2025-14335CRITICAL9.8A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2025-14334CRITICAL9.8A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_ad...
CVE-2025-64672CRITICAL9Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2025-59719CRITICAL9.8An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6...
CVE-2025-59718CRITICAL9.8A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 ...
CVE-2025-34414CRITICAL9.3Entrust Instant Financial Issuance (IFI) On Premise software (formerly referred to as CardWizard) versions 5.x, prior to...
CVE-2025-63742CRITICAL9.8SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA ...
CVE-2025-67504CRITICAL9.8WBCE CMS is a content management system. Versions 1.6.4 and below use function GenerateRandomPassword() to create passwo...
CVE-2025-66631CRITICAL9.8CSLA .NET is a framework designed for the development of reusable, object-oriented business layers for applications. Ver...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now