2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-13806CRITICAL9.8A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of ...
CVE-2025-13800CRITICAL9.8A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the...
CVE-2025-13799CRITICAL9.8A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_...
CVE-2025-13798CRITICAL9.8A flaw has been found in ADSLR NBR1005GPEV2 250814-r037c. This affects the function ap_macfilter_add of the file /send_o...
CVE-2025-13797CRITICAL9.8A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifim...
CVE-2025-35028CRITICAL9.1By providing a command-line argument starting with a semi-colon ; to an API endpoint created by the EnhancedCommandExecu...
CVE-2025-13788CRITICAL9.8A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /t...
CVE-2025-13787CRITICAL9.1A flaw has been found in ZenTao up to 21.7.6-8564. The affected element is the function file::delete of the file module/...
CVE-2025-13786CRITICAL9.8A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fe...
CVE-2025-13783CRITICAL9.8A security flaw has been discovered in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. This affects the fun...
CVE-2025-13782CRITICAL9.8A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is...
CVE-2025-13615CRITICAL9.8The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin...
CVE-2025-66216CRITICAL9.8AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been ident...
CVE-2025-66219CRITICAL9.8willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm...
CVE-2025-66034CRITICAL9.8fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttool...
CVE-2025-65112CRITICAL9.8PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubN...
CVE-2025-66385CRITICAL9.4UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges ...
CVE-2025-12421CRITICAL9.9Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that t...
CVE-2025-12419CRITICAL9.9Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat...
CVE-2025-8890CRITICAL9.3Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman...
CVE-2025-12140CRITICAL9.3The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlP...
CVE-2025-13675CRITICAL9.8The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ...
CVE-2025-13540CRITICAL9.8The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-13539CRITICAL9.8The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,...
CVE-2025-13538CRITICAL9.8The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now