2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57735 | CRITICAL | 9.1 | 0.7% | Apr 9, 2026 | When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t... |
| CVE-2025-52221 | CRITICAL | 9.8 | 0.4% | Apr 8, 2026 | Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and... |
| CVE-2025-14816 | CRITICAL | 9.3 | 0.1% | Apr 8, 2026 | Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and pr... |
| CVE-2025-14815 | CRITICAL | 9.3 | 0.1% | Apr 8, 2026 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi... |
| CVE-2025-69515 | CRITICAL | 9.1 | 0.5% | Apr 7, 2026 | An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int... |
| CVE-2025-71058 | CRITICAL | 9.1 | 0.5% | Apr 7, 2026 | Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originate... |
| CVE-2025-52908 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13... |
| CVE-2025-62818 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-52909 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13... |
| CVE-2025-65115 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - O... |
| CVE-2025-54328 | CRITICAL | 10 | 0.5% | Apr 6, 2026 | An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-58349 | CRITICAL | 9.1 | 0.3% | Apr 6, 2026 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-15484 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant... |
| CVE-2025-71281 | CRITICAL | 9.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in... |
| CVE-2025-71279 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may... |
| CVE-2025-15618 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online... |
| CVE-2025-10559 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE... |
| CVE-2025-15379 | CRITICAL | 9.8 | 2.0% | Mar 30, 2026 | A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_... |
| CVE-2025-15036 | CRITICAL | 10 | 0.6% | Mar 30, 2026 | A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif... |
| CVE-2025-15604 | CRITICAL | 9.8 | 0.5% | Mar 28, 2026 | Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.... |
| CVE-2025-9497 | CRITICAL | 9.8 | 0.3% | Mar 28, 2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This... |
| CVE-2025-55261 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri... |
| CVE-2025-55270 | CRITICAL | 9.8 | 1.0% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ... |
| CVE-2025-55269 | CRITICAL | 9.8 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak... |
| CVE-2025-55267 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now