2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66385CRITICAL9.4UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges ...
CVE-2025-12421CRITICAL9.9Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that t...
CVE-2025-12419CRITICAL9.9Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat...
CVE-2025-8890CRITICAL9.3Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman...
CVE-2025-12140CRITICAL9.3The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlP...
CVE-2025-13675CRITICAL9.8The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ...
CVE-2025-13540CRITICAL9.8The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-13539CRITICAL9.8The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2025-13538CRITICAL9.8The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0...
CVE-2025-62593CRITICAL9.4Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited...
CVE-2025-40934CRITICAL9.3XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can ...
CVE-2025-65276CRITICAL9.8An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/he...
CVE-2025-50433CRITICAL9.8An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted p...
CVE-2025-65669CRITICAL9.1An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without...
CVE-2025-26155CRITICAL9.8NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability...
CVE-2025-64130CRITICAL9.8Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to...
CVE-2025-64128CRITICAL10An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to e...
CVE-2025-64127CRITICAL10An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application a...
CVE-2025-64126CRITICAL10An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter dire...
CVE-2025-55469CRITICAL9.8Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac...
CVE-2025-65236CRITICAL9.8OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID p...
CVE-2025-65235CRITICAL9.8OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via ...
CVE-2025-62354CRITICAL9.8Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized...
CVE-2025-50402CRITICAL9.8FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac...
CVE-2025-50399CRITICAL9.8FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now