2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12004CRITICAL10Incorrect Permission Assignment for Critical Resource vulnerability in The Wikimedia Foundation Mediawiki - Lockdown Ext...
CVE-2025-10916CRITICAL9.1The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path valid...
CVE-2025-7851CRITICAL9.8An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gateways.
CVE-2025-6542CRITICAL9.8An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
CVE-2025-61303CRITICAL9.8Hatching Triage Sandbox Windows 10 build 2004 (2025-08-14) and Windows 10 LTSC 2021(2025-08-14) contains a vulnerability...
CVE-2025-8053CRITICAL9.1Insufficient Granularity of Access Control vulnerability in opentext Flipper allows Exploiting Incorrectly Configured Ac...
CVE-2025-55086CRITICAL9.8In NetXDuo version before 6.4.4, a networking support module for Eclipse Foundation ThreadX, in the DHCPV6 client there ...
CVE-2025-9574CRITICAL10Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects ...
CVE-2025-10678CRITICAL9.3NetBird VPN when installed using vendor's provided script failed to remove or change default password of an admin accoun...
CVE-2025-54957CRITICAL9.8An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+...
CVE-2025-61455CRITICAL9.8SQL Injection vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the signup.inc.php endpoint. The...
CVE-2025-41028CRITICAL9.3A SQL Injection vulnerability has been found in Epsilon RH by Grupo Castilla. This vulnerability allows an attacker to r...
CVE-2025-61932CRITICAL9.8Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of...
CVE-2025-31342CRITICAL9.3An unrestricted upload of file with dangerous type vulnerability in the upload file function of Galaxy Software Services...
CVE-2025-11948CRITICAL9.8Document Management System developed by Excellent Infotek has an Arbitrary File Upload vulnerability, allowing unauthent...
CVE-2025-11943CRITICAL9.8A vulnerability has been found in 70mai X200 up to 20251010. Affected by this vulnerability is an unknown functionality ...
CVE-2025-11942CRITICAL9.8A flaw has been found in 70mai X200 up to 20251010. Affected is an unknown function of the component Pairing. Executing ...
CVE-2025-11391CRITICAL9.8The PPOM – Product Addons & Custom Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads d...
CVE-2025-62650CRITICAL9.9The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for...
CVE-2025-62645CRITICAL9.9The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows a remote authenticated attacker t...
CVE-2025-62515CRITICAL9.8pyquokka is a framework for making data lakes work for time series. In versions 0.3.1 and prior, the FlightServer class ...
CVE-2025-56316CRITICAL9.8A SQL injection vulnerability in the content_title parameter of the /cms/content/list endpoint in MCMS 5.5.0 allows remo...
CVE-2025-56221CRITICAL9.8A lack of rate limiting in the login mechanism of SigningHub v8.6.8 allows attackers to bypass authentication via a brut...
CVE-2025-56218CRITICAL9.8An arbitrary file upload vulnerability in SigningHub v8.6.8 allows attackers to execute arbitrary code via uploading a c...
CVE-2025-34282CRITICAL9.1ThingsBoard versions < 4.2.1 contain a server-side request forgery (SSRF) vulnerability in the dashboard's Image Upload ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now