2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66276CRITICAL9.8QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250...
CVE-2025-10263CRITICAL9.1Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4...
CVE-2025-71318CRITICAL9.8NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated ...
CVE-2025-71317CRITICAL9.8NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce...
CVE-2025-71316CRITICAL9.8SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS...
CVE-2025-67447CRITICAL9.8The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje...
CVE-2025-67446CRITICAL9.8Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u...
CVE-2025-14771CRITICAL9.9Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0...
CVE-2025-53209CRITICAL9.8Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff...
CVE-2025-41277CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41276CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41275CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41274CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41273CRITICAL9.8Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI...
CVE-2025-41272CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41270CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41269CRITICAL9.8Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command...
CVE-2025-41268CRITICAL9.1Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and...
CVE-2025-13392CRITICAL9.8Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7...
CVE-2025-12686CRITICAL9.8Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStati...
CVE-2025-36220CRITICAL9.8IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to...
CVE-2025-71211CRITICAL9.8A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an...
CVE-2025-71210CRITICAL9.8A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an...
CVE-2025-31973CRITICAL9.8HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd...
CVE-2025-33255CRITICAL9.8NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now