2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-64385CRITICAL9.2The equipment initially can be configured using the manufacturer's application, by Wi-Fi, by the web server or with the ...
CVE-2025-57108CRITICAL9.8Kitware VTK (Visualization Toolkit) through 9.5.0 contains a heap use-after-free vulnerability in vtkGLTFDocumentLoader....
CVE-2025-6520CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Abis Technology BA...
CVE-2025-8489CRITICAL9.8The King Addons for Elementor – Free Elements, Widgets, Templates, and Features for Elementor plugin for WordPress is vu...
CVE-2025-5397CRITICAL9.8The Noo JobMonster theme for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.8....
CVE-2025-52665CRITICAL10A malicious actor with access to the management network could exploit a misconfiguration in UniFi’s door access applicat...
CVE-2025-48983CRITICAL9.9A vulnerability in the Mount service of Veeam Backup & Replication, which allows for remote code execution (RCE) on the ...
CVE-2025-34277CRITICAL9.8Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID value...
CVE-2025-34274CRITICAL9.8Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs...
CVE-2025-34271CRITICAL9.8Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the cluster manager component when requesting ...
CVE-2025-3356CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t...
CVE-2025-12516CRITICAL9.8Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12515CRITICAL9.8Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-43027CRITICAL9.8A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attac...
CVE-2025-50739CRITICAL9.8iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization.
CVE-2025-53883CRITICAL9.3A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar...
CVE-2025-54469CRITICAL9.9A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_...
CVE-2025-40099CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed...
CVE-2025-11202CRITICAL9.8win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-11201CRITICAL9.8MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows...
CVE-2025-11200CRITICAL9.8MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp...
CVE-2025-64103CRITICAL9.8Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has...
CVE-2025-64102CRITICAL9.8Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an ...
CVE-2025-12478CRITICAL9.8Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12477CRITICAL9.8Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now