2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52908 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13... |
| CVE-2025-62818 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128... |
| CVE-2025-52909 | CRITICAL | 9.8 | 0.5% | Apr 7, 2026 | An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13... |
| CVE-2025-65115 | CRITICAL | 9.8 | 0.6% | Apr 7, 2026 | Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - O... |
| CVE-2025-54328 | CRITICAL | 10 | 0.5% | Apr 6, 2026 | An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21... |
| CVE-2025-58349 | CRITICAL | 9.1 | 0.3% | Apr 6, 2026 | An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210... |
| CVE-2025-15484 | CRITICAL | 9.1 | 0.2% | Apr 1, 2026 | The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant... |
| CVE-2025-71281 | CRITICAL | 9.8 | 0.3% | Apr 1, 2026 | XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in... |
| CVE-2025-71279 | CRITICAL | 9.8 | 0.5% | Apr 1, 2026 | XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may... |
| CVE-2025-15618 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online... |
| CVE-2025-10559 | CRITICAL | 9.1 | 0.3% | Mar 31, 2026 | A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE... |
| CVE-2025-15379 | CRITICAL | 10 | 2.0% | Mar 30, 2026 | A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_... |
| CVE-2025-15036 | CRITICAL | 10 | 0.6% | Mar 30, 2026 | A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif... |
| CVE-2025-15604 | CRITICAL | 9.8 | 0.5% | Mar 28, 2026 | Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6.... |
| CVE-2025-9497 | CRITICAL | 9.8 | 0.3% | Mar 28, 2026 | Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This... |
| CVE-2025-55261 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri... |
| CVE-2025-55270 | CRITICAL | 9.8 | 1.0% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ... |
| CVE-2025-55269 | CRITICAL | 9.8 | 0.2% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak... |
| CVE-2025-55267 | CRITICAL | 9.8 | 0.3% | Mar 26, 2026 | HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio... |
| CVE-2025-14917 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov... |
| CVE-2025-70888 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the o... |
| CVE-2025-59707 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft becau... |
| CVE-2025-59706 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution. |
| CVE-2025-32991 | CRITICAL | 9 | 0.3% | Mar 25, 2026 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. |
| CVE-2025-33244 | CRITICAL | 9 | 0.6% | Mar 24, 2026 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now