2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-62373CRITICAL9.8Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0...
CVE-2025-50229CRITICAL9.8Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.
CVE-2025-41029CRITICAL9.3SQL injection vulnerability in Zeon Academy Pro by Zeon Global Tech. This vulnerability allows an attacker to retrieve, ...
CVE-2025-15638CRITICAL10Net::Dropbear versions before 0.14 for Perl contains a vulnerable version of libtomcrypt. Net::Dropbear versions before...
CVE-2025-15625CRITICAL9.8Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
CVE-2025-41118CRITICAL9.1Pyroscope is an open-source continuous profiling database. The database supports various storage backends, including Ten...
CVE-2025-15610CRITICAL9.3The .NET Remoting framework used by OpenText Fax (RightFax) includes known security vulnerabilities that could be exploi...
CVE-2025-70023CRITICAL9.8An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
CVE-2025-65135CRITICAL9.8In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin...
CVE-2025-65133CRITICAL9.8A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ...
CVE-2025-63939CRITICAL9.8Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al...
CVE-2025-61260CRITICAL9.8A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ...
CVE-2025-8095CRITICAL9.1The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as crypt...
CVE-2025-31991CRITICAL9.8Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut...
CVE-2025-44560CRITICAL9.8owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking.
CVE-2025-13926CRITICAL9.8An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary request...
CVE-2025-15480CRITICAL9.1In Ubuntu, ubuntu-desktop-provision version 24.04.4 could leak sensitive user credentials during crash reporting. Upon i...
CVE-2025-62718CRITICAL9.9Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.0 and 0.31.0, Axios does not correctly h...
CVE-2025-50228CRITICAL9.1Jizhicms v2.5.4 is vulnerable to Server-Side Request Forgery (SSRF) in User Evaluation, Message, and Comment modules.
CVE-2025-57735CRITICAL9.1When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t...
CVE-2025-52221CRITICAL9.8Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and...
CVE-2025-14816CRITICAL9.3Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and pr...
CVE-2025-14815CRITICAL9.3Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi...
CVE-2025-69515CRITICAL9.1An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int...
CVE-2025-71058CRITICAL9.1Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originate...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now