2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-49380CRITICAL9.8Deserialization of Untrusted Data vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder ...
CVE-2025-49060CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Wastia wastia allows Upload a Web Shell ...
CVE-2025-48106CRITICAL10Unrestricted Upload of File with Dangerous Type vulnerability in CMSSuperHeroes Clanora clanora allows Using Malicious F...
CVE-2025-56447CRITICAL9.8TM2 Monitoring v3.04 contains an authentication bypass and plaintext credential disclosure.
CVE-2025-41108CRITICAL9.8The communication protocol implemented in Ghost Robotics Vision 60 v0.27.2 could allow an attacker to send commands to t...
CVE-2025-41723CRITICAL9.8The importFile SOAP method is vulnerable to a directory traversal attack. An unauthenticated remote attacker bypass the ...
CVE-2025-62481CRITICAL9.8Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support...
CVE-2025-61757CRITICAL9.8Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). Supported vers...
CVE-2025-53072CRITICAL9.8Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration). Support...
CVE-2025-53037CRITICAL9.8Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Servic...
CVE-2025-60772CRITICAL9.8Improper authentication in the web-based management interface of NETLINK HG322G V1.0.00-231017, allows a remote unauthen...
CVE-2025-11534CRITICAL9.3The affected Raisecom devices allow SSH sessions to be established without completing user authentication. This could al...
CVE-2025-11625CRITICAL9.8Improper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypa...
CVE-2025-11624CRITICAL9.8Potential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger...
CVE-2025-10640CRITICAL9.8An unauthenticated attacker with access to TCP port 12306 of the WorkExaminer server can exploit missing server-side aut...
CVE-2025-12004CRITICAL10Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext...
CVE-2025-10916CRITICAL9.1The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-7851CRITICAL9.8An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-6542CRITICAL9.8An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-61303CRITICAL9.8Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability...
CVE-2025-8053CRITICAL9.1Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac...
CVE-2025-55086CRITICAL9.8In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there ...
CVE-2025-9574CRITICAL10Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects ...
CVE-2025-10678CRITICAL9.3NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin accoun...
CVE-2025-54957CRITICAL9.8An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now