2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41008 | CRITICAL | 9.3 | 0.2% | Mar 23, 2026 | SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete d... |
| CVE-2025-41007 | CRITICAL | 9.3 | 0.3% | Mar 23, 2026 | SQL Injection in Cuantis. This vulnerability allows an attacker to retrieve, create, update and delete databases through... |
| CVE-2025-59383 | CRITICAL | 9.1 | 0.3% | Mar 20, 2026 | A buffer overflow vulnerability has been reported to affect Media Streaming Add-On. The remote attackers can then exploi... |
| CVE-2025-15608 | CRITICAL | 9.8 | 0.6% | Mar 20, 2026 | This vulnerability in AX53 v1, AX55 v4 and AX55 v4.6 results from insufficient input sanitization in the device’s probe ... |
| CVE-2025-15607 | CRITICAL | 9.8 | 2.0% | Mar 20, 2026 | A command injection vulnerability on AX53 v1 occurs in mscd debug functionality due to insufficient input handling, allo... |
| CVE-2025-67114 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Use of a deterministic credential generation algorithm in /ftl/bin/calc_f2 in Small Cell Sercomm SCE4255W (FreedomFi Eng... |
| CVE-2025-67113 | CRITICAL | 9.8 | 1.2% | Mar 19, 2026 | OS command injection in the CWMP client (/ftl/bin/cwmp) of Small Cell Sercomm SCE4255W (FreedomFi Englewood) firmware be... |
| CVE-2025-67112 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Use of a hard-coded AES-256-CBC key in the configuration backup/restore implementation of Small Cell Sercomm SCE4255W (F... |
| CVE-2025-71257 | CRITICAL | 9.1 | 5.2% | Mar 19, 2026 | BMC FootPrints ITSM versions 20.20.02 through 20.24.01.001 contain an authentication bypass vulnerability due to imprope... |
| CVE-2025-60237 | CRITICAL | 9.8 | 0.5% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Finag allows Object Injection.This issue affects Finag: from... |
| CVE-2025-60233 | CRITICAL | 9.8 | 0.4% | Mar 19, 2026 | Deserialization of Untrusted Data vulnerability in Themeton Zuut allows Object Injection.This issue affects Zuut: from n... |
| CVE-2025-15031 | CRITICAL | 9.1 | 0.9% | Mar 18, 2026 | A vulnerability in MLflow's pyfunc extraction process allows for arbitrary file writes due to improper handling of tar a... |
| CVE-2025-67830 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortby SQL injection. |
| CVE-2025-67829 | CRITICAL | 9.8 | 0.3% | Mar 18, 2026 | Mura before 10.1.14 allows beanFeed.cfc getQuery sortDirection SQL injection. |
| CVE-2025-69902 | CRITICAL | 9.8 | 2.1% | Mar 16, 2026 | A command injection vulnerability in the minimal_wrapper.py component of kubectl-mcp-server v1.2.0 allows attackers to e... |
| CVE-2025-69809 | CRITICAL | 9.8 | 0.5% | Mar 16, 2026 | A write-what-where condition in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to write arbitrary values t... |
| CVE-2025-69808 | CRITICAL | 9.1 | 0.3% | Mar 16, 2026 | An out-of-bounds memory access (OOB) in p2r3 Bareiron commit 8e4d40 allows unauthenticated attackers to access sensitive... |
| CVE-2025-62319 | CRITICAL | 9.8 | 0.3% | Mar 16, 2026 | Boolean-Based SQL Injection is a type of blind SQL injection where an attacker manipulates SQL queries by injecting Bool... |
| CVE-2025-69246 | CRITICAL | 9.8 | 0.4% | Mar 16, 2026 | Raytha CMS does not have any brute force protection mechanism implemented. It allows an attacker to send multiple automa... |
| CVE-2025-52648 | CRITICAL | 9.8 | 0.1% | Mar 16, 2026 | HCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow ... |
| CVE-2025-15060 | CRITICAL | 9.8 | 1.6% | Mar 16, 2026 | claude-hovercraft executeClaudeCode Command Injection Remote Code Execution Vulnerability. This vulnerability allows rem... |
| CVE-2025-70245 | CRITICAL | 9.8 | 0.6% | Mar 12, 2026 | Stack buffer overflow vulnerability in D-Link DIR-513 v1.10 via the curTime parameter to goform/formSetWizardSelectMode. |
| CVE-2025-59388 | CRITICAL | 9.8 | 0.5% | Mar 12, 2026 | A use of hard-coded password vulnerability has been reported to affect Hyper Data Protector. The remote attackers can th... |
| CVE-2025-70041 | CRITICAL | 9.8 | 0.4% | Mar 11, 2026 | An issue pertaining to CWE-259: Use of Hard-coded Password was discovered in oslabs-beta ThermaKube master. |
| CVE-2025-70024 | CRITICAL | 9.8 | 0.5% | Mar 11, 2026 | An issue pertaining to CWE-89: Improper Neutralization of Special Elements used in an SQL Command was discovered in benk... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now