2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52908CRITICAL9.8An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13...
CVE-2025-62818CRITICAL9.8An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 2100, 128...
CVE-2025-52909CRITICAL9.8An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 13...
CVE-2025-65115CRITICAL9.8Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - O...
CVE-2025-54328CRITICAL10An issue was discovered in SMS in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 21...
CVE-2025-58349CRITICAL9.1An issue was discovered in L2 in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 1080, 210...
CVE-2025-15484CRITICAL9.1The Order Notification for WooCommerce WordPress plugin before 3.6.3 overrides WooCommerce's permission checks to grant...
CVE-2025-71281CRITICAL9.8XenForo before 2.3.7 does not properly restrict methods callable from within templates. A loose prefix match was used in...
CVE-2025-71279CRITICAL9.8XenForo before 2.3.7 contains a security issue affecting Passkeys that have been added to user accounts. An attacker may...
CVE-2025-15618CRITICAL9.1Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::Online...
CVE-2025-10559CRITICAL9.1A Path Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DE...
CVE-2025-15379CRITICAL10A command injection vulnerability exists in MLflow's model serving container initialization code, specifically in the `_...
CVE-2025-15036CRITICAL10A path traversal vulnerability exists in the `extract_archive_to_dir` function within the `mlflow/pyfunc/dbconnect_artif...
CVE-2025-15604CRITICAL9.8Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions 6....
CVE-2025-9497CRITICAL9.8Use of Hard-coded Credentials vulnerability in Microchip Time Provider 4100 allows Malicious Manual Software Update.This...
CVE-2025-55261CRITICAL9.8HCL Aftermarket DPC is affected by Missing Functional Level Access Control which will allow attacker to escalate his pri...
CVE-2025-55270CRITICAL9.8HCL Aftermarket DPC is affected by Improper Input Validation which allows an attacker to inject executable code and can ...
CVE-2025-55269CRITICAL9.8HCL Aftermarket DPC is affected by Weak Password Policy vulnerability, which makes it easier for attackers to guess weak...
CVE-2025-55267CRITICAL9.8HCL Aftermarket DPC is affected by Unrestricted File Upload vulnerability, allows attacker to upload and execute malicio...
CVE-2025-14917CRITICAL9.8IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could prov...
CVE-2025-70888CRITICAL9.8An issue in mtrojnar Osslsigncode affected at v2.10 and before allows a remote attacker to escalate privileges via the o...
CVE-2025-59707CRITICAL9.8In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft becau...
CVE-2025-59706CRITICAL9.8In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution.
CVE-2025-32991CRITICAL9In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution.
CVE-2025-33244CRITICAL9NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now