2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-57735CRITICAL9.1When user logged out, the JWT token the user had authtenticated with was not invalidated, which could lead to reuse of t...
CVE-2025-52221CRITICAL9.8Tenda AC6 15.03.05.16_multi is vulnerable to Buffer Overflow in the formSetCfm function via the funcname, funcpara1, and...
CVE-2025-14816CRITICAL9.3Cleartext Storage of Sensitive Information in GUI vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and pr...
CVE-2025-14815CRITICAL9.3Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mi...
CVE-2025-69515CRITICAL9.1An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system int...
CVE-2025-71058CRITICAL9.1Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originate...
CVE-2025-52908CRITICAL9.8An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13...
CVE-2025-62818CRITICAL9.8An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-52909CRITICAL9.8An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13...
CVE-2025-65115CRITICAL9.8Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - O...
CVE-2025-54328CRITICAL10An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-58349CRITICAL9.1An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-15484CRITICAL9.1The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant...
CVE-2025-71281CRITICAL9.8XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in...
CVE-2025-71279CRITICAL9.8XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may...
CVE-2025-15618CRITICAL9.1Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online...
CVE-2025-10559CRITICAL9.1A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE...
CVE-2025-15379CRITICAL9.8A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_...
CVE-2025-15036CRITICAL10A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif...
CVE-2025-15604CRITICAL9.8Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6....
CVE-2025-9497CRITICAL9.8Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This...
CVE-2025-55261CRITICAL9.8HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri...
CVE-2025-55270CRITICAL9.8HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ...
CVE-2025-55269CRITICAL9.8HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak...
CVE-2025-55267CRITICAL9.8HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now