2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-3356CRITICAL9.8IBM Tivoli Monitoring 6.3.0.7 through 6.3.0.7 Service Pack 21 could allow a remote attacker to traverse directories on t...
CVE-2025-12516CRITICAL9.8Lack of Graceful Error Handling - HTTP 5xx ErrorThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12515CRITICAL9.8Systemic Internal Server Errors - HTTP 500 ResponseThis issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-43027CRITICAL9.8A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attac...
CVE-2025-50739CRITICAL9.8iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization.
CVE-2025-53883CRITICAL9.3A Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability allows attackers to run ar...
CVE-2025-54469CRITICAL9.9A vulnerability was identified in NeuVector, where the enforcer used environment variables CLUSTER_RPC_PORT and CLUSTER_...
CVE-2025-40099CRITICAL9.4In the Linux kernel, the following vulnerability has been resolved: cifs: parse_dfs_referrals: prevent oob on malformed...
CVE-2025-11202CRITICAL9.8win-cli-mcp-server resolveCommandPath Command Injection Remote Code Execution Vulnerability. This vulnerability allows r...
CVE-2025-11201CRITICAL9.8MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows...
CVE-2025-11200CRITICAL9.8MLflow Weak Password Requirements Authentication Bypass Vulnerability. This vulnerability allows remote attackers to byp...
CVE-2025-64103CRITICAL9.8Starting from 2.53.6, 2.54.3, and 2.55.0, Zitadel only required multi factor authentication in case the login policy has...
CVE-2025-64102CRITICAL9.8Zitadel is open-source identity infrastructure software. Prior to 4.6.0, 3.4.3, and 2.71.18, an attacker can perform an ...
CVE-2025-12478CRITICAL9.8Non-Compliant TLS Configuration.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12477CRITICAL9.8Server Version Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-12476CRITICAL9.8Resource Lacking AuthN.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-63622CRITICAL9.8A vulnerability was found in code-projects Online Complaint Site 1.0. This issue affects some unknown processing of the ...
CVE-2025-4665CRITICAL9.6WordPress plugin Contact Form CFDB7 versions up to and including 1.3.2 are affected by a pre-authentication SQL injectio...
CVE-2025-64095CRITICAL9.8DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 1...
CVE-2025-62368CRITICAL9Taiga is an open source project management platform. In versions 6.8.3 and earlier, a remote code execution vulnerabilit...
CVE-2025-43017CRITICAL9.8HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which ...
CVE-2025-61235CRITICAL9.1An issue was discovered in Dataphone A920 v2025.07.161103. A custom packet based on public documentation can be crafted,...
CVE-2025-12424CRITICAL9.8Privilege Escalation through SUID-bit Binary.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5 .
CVE-2025-60355CRITICAL9.8zhangyd-c OneBlog v2.3.9 and before was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
CVE-2025-12422CRITICAL9.8Vulnerable Upgrade Feature (Arbitrary File Write) may lead to obtaining super user permissions on board.This issue affec...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now