2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-11899CRITICAL9.2Agentflow developed by Flowring has an Use of Hard-coded Cryptographic Key vulnerability, allowing unauthenticated remot...
CVE-2025-6893CRITICAL9.3An Execution with Unnecessary Privileges vulnerability has been identified in Moxa’s network security appliances and rou...
CVE-2025-62586CRITICAL9.8OPEXUS FOIAXpress allows a remote, unauthenticated attacker to reset the administrator password. Fixed in FOIAXpress ver...
CVE-2025-61922CRITICAL9.1PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and ...
CVE-2025-34516CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain a use of default credentials vulnerability that allows an...
CVE-2025-34515CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an execution with unnecessary privileges vulnerability in...
CVE-2025-34513CRITICAL9.8Ilevia EVE X1 Server firmware versions ≤ 4.7.18.0.eden contain an OS command injection vulnerability in mbus_build_from_...
CVE-2025-9152CRITICAL9.8An improper privilege management vulnerability exists in WSO2 API Manager due to missing authentication and authorizatio...
CVE-2025-10611CRITICAL9.8Due to an insufficient access control implementation in multiple WSO2 Products, authentication and authorization checks ...
CVE-2025-6338CRITICAL9.2There is an incomplete cleanup vulnerability in Qt Network's Schannel support on Windows which can lead to a Denial of S...
CVE-2025-54539CRITICAL9.8A Deserialization of Untrusted Data vulnerability exists in the Apache ActiveMQ NMS AMQP Client. This issue affects all...
CVE-2025-41019CRITICAL9.3SQL injection in Sergestec's SISTICK v7.2. This vulnerability allows an attacker to retrieve, create, update, and delete...
CVE-2025-41018CRITICAL9.8SQL injection in Sergestec's Exito v8.0. This vulnerability allows an attacker to retrieve, create, update, and delete d...
CVE-2025-62583CRITICAL9.8Whale Browser before 4.33.325.17 allows an attacker to escape the iframe sandbox in a dual-tab environment.
CVE-2025-55089CRITICAL9.8In FileX before 6.4.2, the file support module for Eclipse Foundation ThreadX, there was a possible buffer overflow in t...
CVE-2025-10850CRITICAL9.8The Felan Framework plugin for WordPress is vulnerable to improper authentication in versions up to, and including, 1.1....
CVE-2025-10742CRITICAL9.8The Truelysell Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin...
CVE-2025-11832CRITICAL9.8Allocation of Resources Without Limits or Throttling vulnerability in Azure Access Technology BLU-IC2, Azure Access Tech...
CVE-2025-62410CRITICAL9.4In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating unt...
CVE-2025-20359CRITICAL9.1Multiple Cisco products are affected by a vulnerability in the Snort 3 HTTP Decoder that could allow an unauthenticated,...
CVE-2025-56749CRITICAL9.4Creativeitem Academy LMS up to and including 6.14 uses a hardcoded default JWT secret for token signing. This predictabl...
CVE-2025-53521CRITICAL9.8When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Ex...
CVE-2025-55081CRITICAL9.1In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was...
CVE-2025-9967CRITICAL9.8The Orion SMS OTP Verification plugin for WordPress is vulnerable to privilege escalation via account takeover in all ve...
CVE-2025-10294CRITICAL9.8The OwnID Passwordless Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and incl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now