2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10041CRITICAL9.8The Flex QR Code Generator plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validat...
CVE-2025-39975CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: smb: client: fix wrong index reference in smb2_comp...
CVE-2025-62376CRITICAL9.5pwn.college DOJO is an education platform for learning cybersecurity. Prior to commit 467db0b9ea0d9a929dc89b41f6eb59f7cf...
CVE-2025-49553CRITICAL9.3Adobe Connect versions 12.9 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could ...
CVE-2025-34267CRITICAL9.9Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code exec...
CVE-2025-11736CRITICAL9.8A flaw has been found in itsourcecode Online Examination System 1.0. Affected by this issue is some unknown functionalit...
CVE-2025-59287CRITICAL9.8Deserialization of untrusted data in Windows Server Update Service allows an unauthorized attacker to execute code over ...
CVE-2025-55315CRITICAL9.9Inconsistent interpretation of http requests ('http request/response smuggling') in ASP.NET Core allows an authorized at...
CVE-2025-54603CRITICAL9An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creat...
CVE-2025-49708CRITICAL9.9Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges over a network.
CVE-2025-11548CRITICAL9.3A remote, unauthenticated privilege escalation in ibi WebFOCUS allows an attacker to gain administrative access to the a...
CVE-2025-49201CRITICAL9.8A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions,...
CVE-2025-9064CRITICAL9.1A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on th...
CVE-2025-9063CRITICAL9.8An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exp...
CVE-2025-7328CRITICAL9.8Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing aut...
CVE-2025-11721CRITICAL9.8Memory safety bug present in Firefox 143 and Thunderbird 143. This bug showed evidence of memory corruption and we presu...
CVE-2025-11719CRITICAL9.8Starting in Thunderbird 143, the use of the native messaging API by web extensions on Windows could lead to crashes caus...
CVE-2025-11717CRITICAL9.1When switching between Android apps using the card carousel Firefox shows a black screen as its card image when a passwo...
CVE-2025-11710CRITICAL9.8A compromised web process using malicious IPC messages could have caused the privileged browser process to reveal blocks...
CVE-2025-11709CRITICAL9.8A compromised web process was able to trigger out of bounds reads and writes in a more privileged process using manipula...
CVE-2025-11708CRITICAL9.8Use-after-free in MediaTrackGraphImpl::GetInstance(). This vulnerability was fixed in Firefox 144, Firefox ESR 140.4, Th...
CVE-2025-10610CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SFS Consulting Inf...
CVE-2025-40771CRITICAL9.8A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 154...
CVE-2025-40765CRITICAL9.8A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected...
CVE-2025-46581CRITICAL9.8ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now