2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52648CRITICAL9.8HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ...
CVE-2025-15060CRITICAL9.8claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem...
CVE-2025-70245CRITICAL9.8Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode.
CVE-2025-59388CRITICAL9.8A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can th...
CVE-2025-70041CRITICAL9.8An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master.
CVE-2025-70024CRITICAL9.8An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk...
CVE-2025-66956CRITICAL9.9Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers t...
CVE-2025-70082CRITICAL9.8An issue in Lantronix EDS3000PS v.3.1.0.0R2 allows an attacker to execute arbitrary code and obtain sensitive informatio...
CVE-2025-67041CRITICAL9.8An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The host parameter of the TFTP client in the Filesystem Browse...
CVE-2025-67039CRITICAL9.1An issue was discovered in Lantronix EDS3000PS 3.1.0.0R2. The authentication on management pages can be bypassed by appe...
CVE-2025-67038CRITICAL9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when ...
CVE-2025-67035CRITICAL9.8An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The SSH Client and SSH Server pages are affected by multiple OS ...
CVE-2025-69615CRITICAL9.1Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with n...
CVE-2025-69614CRITICAL9.4Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets...
CVE-2025-56422CRITICAL9.8A deserialization vulnerability in LimeSurvey before v6.15.0+250623 allows a remote attacker to execute arbitrary code o...
CVE-2025-41709CRITICAL9.8An unauthenticated remote attacker can perform a command injection via Modbus-TCP or Modbus-RTU to gain read and write a...
CVE-2025-40943CRITICAL9.6Affected devices do not properly sanitize contents of trace files. This could allow an attacker to inject code throug...
CVE-2025-11158CRITICAL9.1Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restric...
CVE-2025-70039CRITICAL9.8An issue pertaining to CWE-78: Improper Neutralization of Special Elements used in an OS Command was discovered in linag...
CVE-2025-70046CRITICAL9.8An issue pertaining to CWE-829: Inclusion of Functionality from Untrusted Control Sphere was discovered in Miazzy oa-fro...
CVE-2025-70042CRITICAL9.8An issue pertaining to CWE-918: Server-Side Request Forgery was discovered in oslabs-beta ThermaKube master.
CVE-2025-40639CRITICAL9.8A SQL injection vulnerability has been found in Eventobot. This vulnerability allows an attacker to retrieve, create, up...
CVE-2025-41765CRITICAL9.1Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupload.cgi endpoint to...
CVE-2025-41764CRITICAL9.1Due to insufficient authorization enforcement, an unauthorized remote attacker can exploit the wwwupdate.cgi endpoint to...
CVE-2025-59543CRITICAL9Chamilo is a learning management system. Prior to version 1.11.34, there is a stored cross-site scripting (XSS) vulnerab...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now