2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-58750CRITICAL9.1rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58448CRITICAL9.8rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58447CRITICAL9.8rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ...
CVE-2025-58768CRITICAL9.6DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering compo...
CVE-2025-58462CRITICAL9.8OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A r...
CVE-2025-57633CRITICAL9.8A command injection vulnerability in FTP-Flask-python through 5173b68 allows unauthenticated remote attackers to execute...
CVE-2025-43491CRITICAL9.8A vulnerability in the Poly Lens Desktop application running on the Windows platform might allow modifications to the fi...
CVE-2025-23344CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to run code on the platform host as a non-privi...
CVE-2025-23343CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A succ...
CVE-2025-23342CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A succ...
CVE-2025-10159CRITICAL9.8An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi...
CVE-2025-44594CRITICAL9.1halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a...
CVE-2025-55730CRITICAL10XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55729CRITICAL10XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55728CRITICAL9.8XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55727CRITICAL9.8XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55051CRITICAL10CWE-1392: Use of Default Credentials
CVE-2025-55050CRITICAL9.8CWE-1242: Inclusion of Undocumented Features
CVE-2025-55049CRITICAL9.1Use of Default Cryptographic Key (CWE-1394)
CVE-2025-55048CRITICAL9.8Multiple CWE-78
CVE-2025-57085CRITICAL9.8Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function....
CVE-2025-58997CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/...
CVE-2025-55234CRITICAL9.8SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited ...
CVE-2025-55232CRITICAL9.8Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex...
CVE-2025-54261CRITICAL10ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now