2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66568CRITICAL9.1The ruby-saml library implements the client side of an SAML authorization. Versions up to and including 1.12.4, are vuln...
CVE-2025-66567CRITICAL9.1The ruby-saml library is for implementing the client side of a SAML authorization. ruby-saml versions up to and includin...
CVE-2025-66565CRITICAL9.8Fiber Utils is a collection of common functions created for Fiber. In versions 2.0.0-rc.3 and below, when the system's c...
CVE-2025-42928CRITICAL9.1Under certain conditions, a high privileged user could exploit a deserialization vulnerability in SAP jConnect to launch...
CVE-2025-42880CRITICAL9.9Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal...
CVE-2025-40938CRITICAL9.8A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive inf...
CVE-2025-40801CRITICAL9.2A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi...
CVE-2025-40800CRITICAL9.1A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2...
CVE-2025-40343CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvmet-fc: avoid scheduling association deletion twi...
CVE-2025-14330CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 140...
CVE-2025-14326CRITICAL9.8Use-after-free in the Audio/Video: GMP component. This vulnerability was fixed in Firefox 146 and Thunderbird 146.
CVE-2025-14324CRITICAL9.8JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115...
CVE-2025-14321CRITICAL9.8Use-after-free in the WebRTC: Signaling component. This vulnerability was fixed in Firefox 146, Firefox ESR 140.6, Thund...
CVE-2025-14310CRITICAL9.3Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in rethinkdb.This issue affects ret...
CVE-2025-14308CRITICAL9.8An integer overflow vulnerability exists in the write method of the Buffer class in Robocode version 1.9.3.6. The method...
CVE-2025-14306CRITICAL9.1A directory traversal vulnerability exists in the CacheCleaner component of Robocode version 1.9.3.6. The recursivelyDel...
CVE-2025-12504CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UN...
CVE-2025-11022CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This ...
CVE-2025-66481CRITICAL9.6DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable...
CVE-2025-14285CRITICAL9.8A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of th...
CVE-2025-65849CRITICAL9.1A cryptanalytic break in Altcha Proof-of-Work obfuscation mode version 0.8.0 and later allows for remote visitors to rec...
CVE-2025-65548CRITICAL9.1NUT-14 allows cashu tokens to be created with a preimage hash. However, nutshell (cashubtc/nuts) before 0.18.0 do not va...
CVE-2025-64081CRITICAL9.8SQL injection vulnerability in /php/api_patient_schedule.php in SourceCodester Patients Waiting Area Queue Management Sy...
CVE-2025-14258CRITICAL9.8A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2025-48626CRITICAL9.8In multiple locations, there is a possible way to launch an application from the background due to a precondition check ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now