2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-10769CRITICAL9.8A vulnerability has been found in h2oai h2o-3 up to 3.46.08. This affects an unknown function of the file /99/ImportSQLT...
CVE-2025-10768CRITICAL9.8A flaw has been found in h2oai h2o-3 up to 3.46.08. The impacted element is an unknown function of the file /99/ImportSQ...
CVE-2025-6544CRITICAL9.8A deserialization vulnerability exists in h2oai/h2o-3 versions <= 3.46.0.8, allowing attackers to read arbitrary system ...
CVE-2025-40925CRITICAL9.1Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash...
CVE-2025-59431CRITICAL9.8MapServer is a system for developing web-based GIS applications. Prior to 8.4.1, the XML Filter Query directive Property...
CVE-2025-10568CRITICAL9.8HyperX NGENUITY software is potentially vulnerable to arbitrary code execution. HP is releasing updated software to addr...
CVE-2025-34206CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) mount host configu...
CVE-2025-34205CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.192...
CVE-2025-34204CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA and SaaS deployments) contains multiple ...
CVE-2025-34203CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.1002 and Application versions prior t...
CVE-2025-34198CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.951 and Application prior to 20.0.236...
CVE-2025-34195CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330...
CVE-2025-34193CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to...
CVE-2025-34192CRITICAL9.8Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.893 and Application versions prior to...
CVE-2025-48703CRITICAL9CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1205 allows unauthenticated remote code execution via shell...
CVE-2025-57644CRITICAL9.1Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticate...
CVE-2025-5948CRITICAL9.8The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi...
CVE-2025-59717CRITICAL9.8In the @digitalocean/do-markdownit package through 1.16.1 (in npm), the callout and fence_environment plugins perform .i...
CVE-2025-10690CRITICAL9.8The Goza - Nonprofit Charity WordPress Theme theme for WordPress is vulnerable to unauthorized arbitrary file uploads du...
CVE-2025-10035CRITICAL9.8A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged ...
CVE-2025-54807CRITICAL9.8The secret used for validating authentication tokens is hardcoded in device firmware for affected versions. An attacker...
CVE-2025-30519CRITICAL9.8Dover Fueling Solutions ProGauge MagLink LX4 Devices have default root credentials that cannot be changed through standa...
CVE-2025-10689CRITICAL9.8A vulnerability was identified in D-Link DIR-645 105B01. This issue affects the function soapcgi_main of the file /soap....
CVE-2025-10688CRITICAL9.8A vulnerability was determined in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow...
CVE-2025-10687CRITICAL9.8A vulnerability was found in SourceCodester Responsive E-Learning System 1.0. This affects an unknown part of the file /...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now