2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-40934CRITICAL9.3XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can ...
CVE-2025-65276CRITICAL9.8An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/he...
CVE-2025-50433CRITICAL9.8An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted p...
CVE-2025-65669CRITICAL9.1An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without...
CVE-2025-26155CRITICAL9.8NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability...
CVE-2025-64130CRITICAL9.8Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to...
CVE-2025-64128CRITICAL10An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to e...
CVE-2025-64127CRITICAL10An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application a...
CVE-2025-64126CRITICAL10An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter dire...
CVE-2025-55469CRITICAL9.8Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac...
CVE-2025-65236CRITICAL9.8OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID p...
CVE-2025-65235CRITICAL9.8OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via ...
CVE-2025-62354CRITICAL9.8Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized...
CVE-2025-50402CRITICAL9.8FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac...
CVE-2025-50399CRITICAL9.8FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password.
CVE-2025-59390CRITICAL9.8Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign...
CVE-2025-66022CRITICAL9.8FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa...
CVE-2025-66266CRITICAL9.3The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control....
CVE-2025-66262CRITICAL9.8Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit...
CVE-2025-66261CRITICAL9.8Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66259CRITICAL9.8Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo...
CVE-2025-66257CRITICAL9.1Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm...
CVE-2025-66256CRITICAL9.8Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit...
CVE-2025-66255CRITICAL9.8Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm...
CVE-2025-66254CRITICAL9.1Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now