2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-61044CRITICAL9.8TOTOLINK X18 V9.1.0cu.2053_B20230309 was discovered to contain a command injection vulnerability via the agentName param...
CVE-2025-61622CRITICAL9.8Deserialization of untrusted data in python in pyfory versions 0.12.0 through 0.12.2, or the legacy pyfury versions from...
CVE-2025-10659CRITICAL9.8The Telenium Online Web Application is vulnerable due to a PHP endpoint accessible to unauthenticated network users that...
CVE-2025-56513CRITICAL9.8NiceHash QuickMiner 6.12.0 perform software updates over HTTP without validating digital signatures or hash checks. An a...
CVE-2025-10725CRITICAL9.9A flaw was found in Red Hat Openshift AI Service. A low-privileged attacker with access to an authenticated account, for...
CVE-2025-7493CRITICAL9.1A privilege escalation flaw from host to domain administrator was found in FreeIPA. This vulnerability is similar to CVE...
CVE-2025-34217CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) contain an undocumente...
CVE-2025-9762CRITICAL9.8The Post By Email plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th...
CVE-2025-8625CRITICAL9.8The Copypress Rest API plugin for WordPress is vulnerable to Remote Code Execution via copyreap_handle_image() Function ...
CVE-2025-8120CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's upload photo functionality allows an unauthenticated remo...
CVE-2025-7065CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remo...
CVE-2025-7063CRITICAL9.8Due to client-controlled permission check parameter, PAD CMS's file upload functionality allows an unauthenticated remot...
CVE-2025-61584CRITICAL9.3serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions th...
CVE-2025-59954CRITICAL9.8Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote ...
CVE-2025-11148CRITICAL9.8All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha...
CVE-2025-59937CRITICAL9.1go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of ...
CVE-2025-54875CRITICAL9.8FreshRSS is a free, self-hostable RSS aggregator. In versions 1.16.0 and above through 1.26.3, an unprivileged attacker ...
CVE-2025-54592CRITICAL9.8FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not properly terminate the session during...
CVE-2025-57266CRITICAL9.8An issue was discovered in file AssistantController.java in ThriveX Blogging Framework 2.5.9 thru 3.1.3 allowing unauthe...
CVE-2025-34224CRITICAL9.1Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ...
CVE-2025-34223CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ...
CVE-2025-34222CRITICAL9.1Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ...
CVE-2025-34221CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.2.169 and Application prior to version 2...
CVE-2025-34218CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1049 and Application prior to version ...
CVE-2025-34216CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 22.0.1026 and Application prior to version ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now