2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14917 | CRITICAL | 9.8 | 0.4% | Mar 25, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov... |
| CVE-2025-70888 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the o... |
| CVE-2025-59707 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft becau... |
| CVE-2025-59706 | CRITICAL | 9.8 | 0.5% | Mar 25, 2026 | In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution. |
| CVE-2025-32991 | CRITICAL | 9 | 0.3% | Mar 25, 2026 | In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. |
| CVE-2025-33244 | CRITICAL | 9 | 0.6% | Mar 24, 2026 | NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted... |
| CVE-2025-41008 | CRITICAL | 9.3 | 0.2% | Mar 23, 2026 | SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d... |
| CVE-2025-41007 | CRITICAL | 9.3 | 0.3% | Mar 23, 2026 | SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through... |
| CVE-2025-59383 | CRITICAL | 9.1 | 0.3% | Mar 20, 2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi... |
| CVE-2025-15608 | CRITICAL | 9.8 | 0.5% | Mar 20, 2026 | This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe ... |
| CVE-2025-15607 | CRITICAL | 9.8 | 2.0% | Mar 20, 2026 | A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo... |
| CVE-2025-67114 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng... |
| CVE-2025-67113 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be... |
| CVE-2025-67112 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F... |
| CVE-2025-71257 | CRITICAL | 9.1 | 5.2% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope... |
| CVE-2025-60237 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from... |
| CVE-2025-60233 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n... |
| CVE-2025-15031 | CRITICAL | 9.1 | 0.9% | Mar 18, 2026 | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a... |
| CVE-2025-67830 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. |
| CVE-2025-67829 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. |
| CVE-2025-69902 | CRITICAL | 9.8 | 2.1% | Mar 16, 2026 | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e... |
| CVE-2025-69809 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values t... |
| CVE-2025-69808 | CRITICAL | 9.1 | 0.3% | Mar 16, 2026 | An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive... |
| CVE-2025-62319 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool... |
| CVE-2025-69246 | CRITICAL | 9.8 | 0.4% | Mar 16, 2026 | Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now