2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66276 | CRITICAL | 9.8 | 0.3% | Jun 10, 2026 | QuTS hero is not affected. We have already fixed the vulnerability in the following version: QTS 5.2.7.3256 build 20250... |
| CVE-2025-10263 | CRITICAL | 9.1 | 0.6% | Jun 9, 2026 | Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4... |
| CVE-2025-71318 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated ... |
| CVE-2025-71317 | CRITICAL | 9.8 | 0.4% | Jun 5, 2026 | NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative acce... |
| CVE-2025-71316 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Windows C runtime converts Unicode characters to ANS... |
| CVE-2025-67447 | CRITICAL | 9.8 | 1.0% | Jun 4, 2026 | The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command inje... |
| CVE-2025-67446 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router u... |
| CVE-2025-14771 | CRITICAL | 9.9 | 0.3% | Jun 3, 2026 | Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0... |
| CVE-2025-53209 | CRITICAL | 9.8 | 0.3% | Jun 2, 2026 | Incorrect Privilege Assignment vulnerability in Themeisle Masteriyo LMS PRO allows Privilege Escalation. This issue aff... |
| CVE-2025-41277 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41276 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41275 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41274 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41273 | CRITICAL | 9.8 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-288: Authentication Bypass Using an Alternate Path or Channel in the Console WebUI... |
| CVE-2025-41272 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41270 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41269 | CRITICAL | 9.8 | 1.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command... |
| CVE-2025-41268 | CRITICAL | 9.1 | 0.4% | May 29, 2026 | Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and... |
| CVE-2025-13392 | CRITICAL | 9.8 | 0.5% | May 27, 2026 | Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7... |
| CVE-2025-12686 | CRITICAL | 9.8 | 2.8% | May 27, 2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStati... |
| CVE-2025-36220 | CRITICAL | 9.8 | 0.3% | May 26, 2026 | IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System is vulnerable to... |
| CVE-2025-71211 | CRITICAL | 9.8 | 3.8% | May 21, 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... |
| CVE-2025-71210 | CRITICAL | 9.8 | 3.8% | May 21, 2026 | A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code an... |
| CVE-2025-31973 | CRITICAL | 9.8 | 0.2% | May 20, 2026 | HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outd... |
| CVE-2025-33255 | CRITICAL | 9.8 | 0.6% | May 20, 2026 | NVIDIA TRT-LLM for any platform contains a vulnerability in MPI server, where an attacker could cause an unsafe deserial... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now