2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-62596CRITICAL10Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie...
CVE-2025-62161CRITICAL10Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul...
CVE-2025-63334CRITICAL9.8PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm...
CVE-2025-63416CRITICAL9.1** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the Self...
CVE-2025-55343CRITICAL9.9Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d...
CVE-2025-56231CRITICAL9.1Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta...
CVE-2025-10713CRITICAL9.1An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML par...
CVE-2025-45378CRITICAL9.1Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass...
CVE-2025-20358CRITICAL9.8A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticat...
CVE-2025-20354CRITICAL9.8A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, ...
CVE-2025-63601CRITICAL9.9Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to up...
CVE-2025-61304CRITICAL9.8OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address.
CVE-2025-64459CRITICAL9.1An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, ...
CVE-2025-47151CRITICAL9.8A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 ...
CVE-2025-55108CRITICAL10The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un...
CVE-2025-12674CRITICAL9.8The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-11749CRITICAL9.8The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,...
CVE-2025-12735CRITICAL9.8The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio...
CVE-2025-52910CRITICAL9.8An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 148...
CVE-2025-47776CRITICAL9.1Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===...
CVE-2025-12108CRITICAL9.3The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration...
CVE-2025-61956CRITICAL9.8Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access an...
CVE-2025-61945CRITICAL9.8Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without auth...
CVE-2025-54863CRITICAL9.8Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration f...
CVE-2025-12682CRITICAL9.8The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now