2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-11717CRITICAL9.1When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a passwo...
CVE-2025-11710CRITICAL9.8A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks...
CVE-2025-11709CRITICAL9.8A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipula...
CVE-2025-11708CRITICAL9.8Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Th...
CVE-2025-10610CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Inf...
CVE-2025-40771CRITICAL9.8A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 154...
CVE-2025-40765CRITICAL9.8A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected...
CVE-2025-46581CRITICAL9.8ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can ...
CVE-2025-42937CRITICAL9.8SAP Print Service (SAPSprint) performs insufficient validation of path information provided by users. An unauthenticated...
CVE-2025-42910CRITICAL9Due to missing verification of file type or content, SAP Supplier Relationship Management allows an authenticated attack...
CVE-2025-6919CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cats Information T...
CVE-2025-9976CRITICAL9An OS Command Injection vulnerability affecting Station Launcher App in 3DEXPERIENCE platform from Release 3DEXPERIENCE ...
CVE-2025-9265CRITICAL10A broken authorization vulnerability in Kiloview NDI N30 allows a remote unauthenticated attacker to deactivate user ver...
CVE-2025-27258CRITICAL9.8Ericsson Network Manager (ENM) versions prior to ENM 25.1 GA contain a vulnerability, if exploited, can result in an esc...
CVE-2025-11665CRITICAL9.8A vulnerability was detected in D-Link DAP-2695 2.00RC131. This affects the function fwupdater_main of the file rgbin of...
CVE-2025-11664CRITICAL9.8A security vulnerability has been detected in Campcodes Online Beauty Parlor Management System 1.0. The impacted element...
CVE-2025-11662CRITICAL9.8A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. Impacted is an unknown function ...
CVE-2025-11661CRITICAL9.8A vulnerability was found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59...
CVE-2025-11660CRITICAL9.8A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90...
CVE-2025-11659CRITICAL9.8A flaw has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Af...
CVE-2025-11658CRITICAL9.8A vulnerability was detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042...
CVE-2025-11657CRITICAL9.8A security vulnerability has been detected in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd...
CVE-2025-11656CRITICAL9.8A weakness has been identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f90...
CVE-2025-36087CRITICAL9.8IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, an...
CVE-2025-11631CRITICAL9.1A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functional...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now