2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-14320CRITICAL9.8Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management...
CVE-2025-71284CRITICAL9.8Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoi...
CVE-2025-14543CRITICAL9.1Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Core Libraries) allows ...
CVE-2025-13030CRITICAL9.8All versions of the package django-mdeditor are vulnerable to Missing Authentication for Critical Function in the image ...
CVE-2025-60889CRITICAL9.8Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to e...
CVE-2025-62373CRITICAL9.8Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0...
CVE-2025-50229CRITICAL9.8Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
CVE-2025-41029CRITICAL9.3SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, ...
CVE-2025-15638CRITICAL10Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before...
CVE-2025-15625CRITICAL9.8Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
CVE-2025-41118CRITICAL9.1Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten...
CVE-2025-15610CRITICAL9.3The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi...
CVE-2025-14813CRITICAL9.3: Use of a Broken or Risky Cryptographic Algorithm vulnerability in Legion of the Bouncy Castle Inc. BC-JAVA bcprov on a...
CVE-2025-70023CRITICAL9.8An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
CVE-2025-65135CRITICAL9.8In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin...
CVE-2025-65133CRITICAL9.8A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ...
CVE-2025-63939CRITICAL9.8Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al...
CVE-2025-61260CRITICAL9.8A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ...
CVE-2025-8095CRITICAL9.1The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as crypt...
CVE-2025-31991CRITICAL9.8Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut...
CVE-2025-44560CRITICAL9.8owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.
CVE-2025-13926CRITICAL9.8An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request...
CVE-2025-15480CRITICAL9.1In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i...
CVE-2025-62718CRITICAL9.9Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h...
CVE-2025-50228CRITICAL9.1Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now