2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-59390CRITICAL9.8Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign...
CVE-2025-66022CRITICAL9.8FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa...
CVE-2025-66266CRITICAL9.3The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control....
CVE-2025-66262CRITICAL9.8Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit...
CVE-2025-66261CRITICAL9.8Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66259CRITICAL9.8Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo...
CVE-2025-66257CRITICAL9.1Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm...
CVE-2025-66256CRITICAL9.8Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit...
CVE-2025-66255CRITICAL9.8Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm...
CVE-2025-66254CRITICAL9.1Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran...
CVE-2025-66253CRITICAL9.8Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte...
CVE-2025-66251CRITICAL9.1Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66250CRITICAL9.8Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-64657CRITICAL9.8Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a ne...
CVE-2025-64656CRITICAL9.8Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-13597CRITICAL9.8The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual...
CVE-2025-13595CRITICAL9.8The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu...
CVE-2025-58360CRITICAL9.8GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2....
CVE-2025-51746CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjso...
CVE-2025-51745CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization...
CVE-2025-51744CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserializatio...
CVE-2025-51743CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to...
CVE-2025-66016CRITICAL9.3CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab...
CVE-2025-51742CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the...
CVE-2025-64063CRITICAL9.8Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now