2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-41008CRITICAL9.3SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d...
CVE-2025-41007CRITICAL9.3SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through...
CVE-2025-59383CRITICAL9.1A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi...
CVE-2025-15608CRITICAL9.8This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe ...
CVE-2025-15607CRITICAL9.8A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo...
CVE-2025-67114CRITICAL9.8Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng...
CVE-2025-67113CRITICAL9.8OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be...
CVE-2025-67112CRITICAL9.8Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F...
CVE-2025-71257CRITICAL9.1BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope...
CVE-2025-60237CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from...
CVE-2025-60233CRITICAL9.8Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n...
CVE-2025-15031CRITICAL9.1A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a...
CVE-2025-67830CRITICAL9.8Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection.
CVE-2025-67829CRITICAL9.8Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection.
CVE-2025-69902CRITICAL9.8A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e...
CVE-2025-69809CRITICAL9.8A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values t...
CVE-2025-69808CRITICAL9.1An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive...
CVE-2025-62319CRITICAL9.8Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool...
CVE-2025-69246CRITICAL9.8Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa...
CVE-2025-52648CRITICAL9.8HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ...
CVE-2025-15060CRITICAL9.8claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2025-70245CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.
CVE-2025-59388CRITICAL9.8A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can th...
CVE-2025-70041CRITICAL9.8An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.
CVE-2025-70024CRITICAL9.8An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now