2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-14094CRITICAL9.8A flaw has been found in Edimax BR-6478AC V3 1.0.15. The affected element is the function sub_44CCE4 of the file /boafrm...
CVE-2025-14093CRITICAL9.8A vulnerability was detected in Edimax BR-6478AC V3 1.0.15. Impacted is the function sub_416990 of the file /boafrm/form...
CVE-2025-64054CRITICAL9.6A reflected Cross Site Scripting (XSS) vulnerability on Fanvil x210 2.12.20 devices allows attackers to cause a denial o...
CVE-2025-12374CRITICAL9.8The Email Verification, Email OTP, Block Spam Email, Passwordless login, Hide Login, Magic Login – User Verification plu...
CVE-2025-13313CRITICAL9.8The CRM Memberships plugin for WordPress is vulnerable to privilege escalation via password reset in all versions up to,...
CVE-2025-66509CRITICAL9.8LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow tr...
CVE-2025-66576CRITICAL9.8Remote Keyboard Desktop 1.0.1 enables remote attackers to execute system commands via the rundll32.exe exported function...
CVE-2025-66571CRITICAL9.3UNA CMS versions 9.0.0-RC1 - 14.0.0-RC4 contain a PHP object injection vulnerability in BxBaseMenuSetAclLevel.php where ...
CVE-2025-29269CRITICAL9.8ALLNET ALL-RUT22GW v3.3.8 was discovered to contain an OS command injection vulnerability via the command parameter in t...
CVE-2025-29268CRITICAL9.8ALLNET ALL-RUT22GW v3.3.8 was discovered to store hardcoded credentials in the libicos.so library.
CVE-2025-12995CRITICAL9.8Medtronic CareLink Network allows an unauthenticated remote attacker to perform a brute force attack on an API endpoint ...
CVE-2025-63362CRITICAL9.8Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00...
CVE-2025-14015CRITICAL9.8A weakness has been identified in H3C Magic B0 up to 100R002. This impacts the function EditWlanMacList of the file /gof...
CVE-2025-66516CRITICAL9.8Critical XXE in Apache Tika tika-core (1.13-3.2.1), tika-pdf-module (2.0.0-3.2.1) and tika-parsers (1.13-1.28.5) modules...
CVE-2025-40261CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nvme: nvme-fc: Ensure ->ioerr_work is cancelled in ...
CVE-2025-40258CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: mptcp: fix race condition in mptcp_schedule_work() ...
CVE-2025-40257CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: mptcp: fix a race in mptcp_pm_del_add_timer() mptc...
CVE-2025-40252CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: net: qlogic/qede: fix potential out-of-bounds read ...
CVE-2025-65346CRITICAL9.1alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The unzip/extraction functionality ...
CVE-2025-54304CRITICAL9.8An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. When they are powered on, an X11 dis...
CVE-2025-54303CRITICAL9.8The Thermo Fisher Torrent Suite Django application 5.18.1 has weak default credentials, which are stored as fixtures for...
CVE-2025-53963CRITICAL9.8An issue was discovered on Thermo Fisher Ion Torrent OneTouch 2 INS1005527 devices. They run an SSH server accessible ov...
CVE-2025-14004CRITICAL9.8A security flaw has been discovered in dayrui XunRuiCMS up to 4.7.1. Affected is an unknown function of the file /admind...
CVE-2025-64055CRITICAL9.8An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access admi...
CVE-2025-66489CRITICAL9.8Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now