2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-41064CRITICAL9.3Incorrect authentication vulnerability in OpenSIAC, which could allow an attacker to impersonate a person using Cl@ve as...
CVE-2025-9697CRITICAL9.8The Ajax WooSearch WordPress plugin through 1.0.0 does not properly sanitise and escape a parameter before using it in a...
CVE-2025-11221CRITICAL9.4Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Unrestricted Upload of File with Dangero...
CVE-2025-61588CRITICAL9.3RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture....
CVE-2025-59951CRITICAL9.1Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The offici...
CVE-2025-59681CRITICAL9.8An issue was discovered in Django 4.2 before 4.2.25, 5.1 before 5.1.13, and 5.2 before 5.2.7. QuerySet.annotate(), Query...
CVE-2025-8679CRITICAL9.8In ExtremeGuest Essentials before 25.5.0, captive-portal may permit unauthorized access via manual brute-force procedure...
CVE-2025-61045CRITICAL9.8TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the mac parameter i...
CVE-2025-61044CRITICAL9.8TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param...
CVE-2025-61622CRITICAL9.8Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from...
CVE-2025-10659CRITICAL9.8The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that...
CVE-2025-56513CRITICAL9.8NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a...
CVE-2025-10725CRITICAL9.9A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for...
CVE-2025-7493CRITICAL9.1A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE...
CVE-2025-34217CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente...
CVE-2025-9762CRITICAL9.8The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-8625CRITICAL9.8The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function ...
CVE-2025-8120CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo...
CVE-2025-7065CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remo...
CVE-2025-7063CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remot...
CVE-2025-61584CRITICAL9.3serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions th...
CVE-2025-59954CRITICAL9.8Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote ...
CVE-2025-11148CRITICAL9.8All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha...
CVE-2025-59937CRITICAL9.1go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of ...
CVE-2025-54875CRITICAL9.8FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now