2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-36220CRITICAL9.8IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to...
CVE-2025-71211CRITICAL9.8A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an...
CVE-2025-71210CRITICAL9.8A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an...
CVE-2025-31973CRITICAL9.8HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd...
CVE-2025-33255CRITICAL9.8NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial...
CVE-2025-11024CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So...
CVE-2025-27851CRITICAL9.3The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attac...
CVE-2025-65719CRITICAL9.8An issue in Open Source Kubectl MCP Server v1.1.1 allows attackers to execute arbitrary code on a victim system via user...
CVE-2025-6577CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce So...
CVE-2025-40949CRITICAL9.1A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versio...
CVE-2025-14179CRITICAL9.8In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird ...
CVE-2025-69691CRITICAL9.9Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this ...
CVE-2025-69690CRITICAL9.1Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP ob...
CVE-2025-69599CRITICAL9.8RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH e...
CVE-2025-67887CRITICAL9.81C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Transla...
CVE-2025-63704CRITICAL9.8NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user ...
CVE-2025-63703CRITICAL9.8npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
CVE-2025-63706CRITICAL9.8NPM package next-npm-version1.0.1 is vulnerable to Command injection.
CVE-2025-1978CRITICAL9.8Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage ...
CVE-2025-9661CRITICAL9.8OS command injection vulneravility in the management gui (maintenance utility) of Hitachi Virtual Storage Platform One B...
CVE-2025-59852CRITICAL9.1HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted ove...
CVE-2025-59851CRITICAL9.8HCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatc...
CVE-2025-13618CRITICAL9.8The Mentoring plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.2.8. Th...
CVE-2025-13605CRITICAL9.33onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to exec...
CVE-2025-70067CRITICAL9.8Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiM...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now