2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10850CRITICAL9.8The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1....
CVE-2025-10742CRITICAL9.8The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin...
CVE-2025-11832CRITICAL9.8Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech...
CVE-2025-62410CRITICAL9.4In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating unt...
CVE-2025-56749CRITICAL9.4Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictabl...
CVE-2025-53521CRITICAL9.8When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex...
CVE-2025-55081CRITICAL9.1In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was...
CVE-2025-9967CRITICAL9.8The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve...
CVE-2025-10294CRITICAL9.8The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl...
CVE-2025-10041CRITICAL9.8The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-39975CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp...
CVE-2025-62376CRITICAL9.5pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cf...
CVE-2025-49553CRITICAL9.3Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could ...
CVE-2025-34267CRITICAL9.9Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec...
CVE-2025-11736CRITICAL9.8A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit...
CVE-2025-59287CRITICAL9.8Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over ...
CVE-2025-55315CRITICAL9.9Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at...
CVE-2025-49708CRITICAL9.9Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
CVE-2025-11548CRITICAL9.3A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the a...
CVE-2025-49201CRITICAL9.8A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions,...
CVE-2025-9064CRITICAL9.1A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on th...
CVE-2025-9063CRITICAL9.8An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exp...
CVE-2025-7328CRITICAL9.8Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut...
CVE-2025-11721CRITICAL9.8Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presu...
CVE-2025-11719CRITICAL9.8Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now