2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-14199CRITICAL9.8A flaw has been found in Verysync 微力同步 up to 2.21.3. This impacts an unknown function of the file /rest/f/api/resources/...
CVE-2025-14191CRITICAL9.8A vulnerability has been found in UTT 进取 512W up to 1.7.7-171114. Affected by this issue is the function strcpy of the f...
CVE-2025-14182CRITICAL9.8A vulnerability has been found in Sobey Media Convergence System 2.0/2.1. This vulnerability affects unknown code of the...
CVE-2025-14141CRITICAL9.8A flaw has been found in UTT 进取 520W 1.7.7-180627. The impacted element is the function strcpy of the file /goform/formA...
CVE-2025-12673CRITICAL9.8The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-66644CRITICAL9.8Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as exploited in the wild in August through December 2...
CVE-2025-66570CRITICAL9.8cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.27.0, a vulnerability allow...
CVE-2025-66562CRITICAL9.6TUUI is a desktop MCP client designed as a tool unitary utility integration. Prior to 1.3.4, a critical Remote Code Exec...
CVE-2025-34256CRITICAL9.8Advantech WISE-DeviceOn Server versions prior to 5.4 contain a hard-coded cryptographic key vulnerability. The product u...
CVE-2025-14094CRITICAL9.8A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm...
CVE-2025-14093CRITICAL9.8A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/form...
CVE-2025-64054CRITICAL9.6A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial o...
CVE-2025-12374CRITICAL9.8The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plu...
CVE-2025-13313CRITICAL9.8The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,...
CVE-2025-66509CRITICAL9.8LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow tr...
CVE-2025-66576CRITICAL9.8Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function...
CVE-2025-66571CRITICAL9.3UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where ...
CVE-2025-29269CRITICAL9.8ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t...
CVE-2025-29268CRITICAL9.8ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
CVE-2025-12995CRITICAL9.8Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint ...
CVE-2025-63362CRITICAL9.8Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-14015CRITICAL9.8A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /gof...
CVE-2025-66516CRITICAL9.8Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules...
CVE-2025-40261CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in ...
CVE-2025-40258CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now