2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-8414CRITICAL9.4Due to improper input validation, a buffer overflow vulnerability is present in Zigbee EZSP Host Applications. If the ...
CVE-2025-62353CRITICAL9.8A path traversal vulnerability in all versions of the Windsurf IDE enables a threat actor to read and write arbitrary lo...
CVE-2025-60279CRITICAL9.6A server-side request forgery (SSRF) vulnerability in Illia Cloud illia-Builder before v4.8.5 allows authenticated users...
CVE-2025-57567CRITICAL9.1A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file l...
CVE-2025-49655CRITICAL9.8Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not inc...
CVE-2025-55100CRITICAL9.1In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read iss...
CVE-2025-11849CRITICAL9.3Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1....
CVE-2025-6950CRITICAL9.9An Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. Th...
CVE-2025-6949CRITICAL9.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-11900CRITICAL9.8The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to...
CVE-2025-11899CRITICAL9.2Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remot...
CVE-2025-6893CRITICAL9.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-62586CRITICAL9.8OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver...
CVE-2025-61922CRITICAL9.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and ...
CVE-2025-34516CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an...
CVE-2025-34515CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in...
CVE-2025-34513CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_...
CVE-2025-9152CRITICAL9.8An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio...
CVE-2025-10611CRITICAL9.8Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks ...
CVE-2025-6338CRITICAL9.2There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of S...
CVE-2025-54539CRITICAL9.8A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all...
CVE-2025-41019CRITICAL9.3SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete...
CVE-2025-41018CRITICAL9.8SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d...
CVE-2025-62583CRITICAL9.8Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CVE-2025-55089CRITICAL9.8In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now