2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-40257CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptc...
CVE-2025-40252CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read ...
CVE-2025-65346CRITICAL9.1alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality ...
CVE-2025-54304CRITICAL9.8An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 dis...
CVE-2025-54303CRITICAL9.8The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for...
CVE-2025-53963CRITICAL9.8An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible ov...
CVE-2025-14004CRITICAL9.8A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind...
CVE-2025-64055CRITICAL9.8An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access admi...
CVE-2025-66489CRITICAL9.8Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker ...
CVE-2025-66222CRITICAL9.6DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting...
CVE-2025-66208CRITICAL9.8Collabora Online - Built-in CODE Server (richdocumentscode) provides a built-in server with all of the document editing ...
CVE-2025-66032CRITICAL9.8Claude Code is an agentic coding tool. Prior to 1.0.93, Due to errors in parsing shell commands related to $IFS and shor...
CVE-2025-64443CRITICAL9.6MCP Gateway allows easy and secure running and deployment of MCP servers. In versions 0.27.0 and earlier, when MCP Gatew...
CVE-2025-34319CRITICAL9.3TOTOLINK N300RT wireless router firmware versions prior to V3.4.0-B20250430 (discovered in V2.1.8-B20201030.1539) contai...
CVE-2025-55182CRITICAL10A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1...
CVE-2025-65267CRITICAL9In ERPNext v15.83.2 and Frappe Framework v15.86.0, improper validation of uploaded SVG avatar images allows attackers to...
CVE-2025-13390CRITICAL9.8The WP Directory Kit plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1...
CVE-2025-13342CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress ...
CVE-2025-13486CRITICAL9.8The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to Remote Code Execution in versions 0.9.0.5 thr...
CVE-2025-13658CRITICAL9.3A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e...
CVE-2025-13542CRITICAL9.8The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-13510CRITICAL9.3The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio...
CVE-2025-66409CRITICAL9.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earli...
CVE-2025-65896CRITICAL9.8SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via craf...
CVE-2025-60736CRITICAL9.8code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now