2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-66253CRITICAL9.8Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte...
CVE-2025-66251CRITICAL9.1Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-66250CRITICAL9.8Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi...
CVE-2025-64657CRITICAL9.8Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a ne...
CVE-2025-64656CRITICAL9.8Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-13597CRITICAL9.8The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual...
CVE-2025-13595CRITICAL9.8The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu...
CVE-2025-58360CRITICAL9.8GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2....
CVE-2025-51746CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjso...
CVE-2025-51745CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization...
CVE-2025-51744CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserializatio...
CVE-2025-51743CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to...
CVE-2025-66016CRITICAL9.3CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab...
CVE-2025-51742CRITICAL9.8An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the...
CVE-2025-64063CRITICAL9.8Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif...
CVE-2025-61168CRITICAL9.8An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializin...
CVE-2025-65085CRITICAL9.8A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v...
CVE-2025-65084CRITICAL9.8An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version...
CVE-2025-63729CRITICAL9An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Pr...
CVE-2025-60739CRITICAL9.6Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logi...
CVE-2025-64693CRITICAL9.8Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Con...
CVE-2025-62691CRITICAL9.8Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HT...
CVE-2025-59366CRITICAL9.2An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effe...
CVE-2025-13559CRITICAL9.8The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. ...
CVE-2025-6389CRITICAL9.8The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now