2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-23343CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to write files to restricted components. A succ...
CVE-2025-23342CRITICAL9.8The NVIDIA NVDebug tool contains a vulnerability that may allow an actor to gain access to a privileged account . A succ...
CVE-2025-10159CRITICAL9.8An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wi...
CVE-2025-44594CRITICAL9.1halo v2.20.17 and before is vulnerable to server-side request forgery (SSRF) in /apis/uc.api.storage.halo.run/v1alpha1/a...
CVE-2025-55730CRITICAL10XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55729CRITICAL10XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55728CRITICAL9.8XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55727CRITICAL9.8XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in ...
CVE-2025-55051CRITICAL10CWE-1392: Use of Default Credentials
CVE-2025-55050CRITICAL9.8CWE-1242: Inclusion of Undocumented Features
CVE-2025-55049CRITICAL9.1Use of Default Cryptographic Key (CWE-1394)
CVE-2025-55048CRITICAL9.8Multiple CWE-78
CVE-2025-57085CRITICAL9.8Tenda W30E V16.01.0.19 (5037) was discovered to contain a stack overflow in the v17 parameter in the UploadCfg function....
CVE-2025-58997CRITICAL9.6Cross-Site Request Forgery (CSRF) vulnerability in Frenify Mow mow allows Code Injection.This issue affects Mow: from n/...
CVE-2025-55234CRITICAL9.8SMB Server might be susceptible to relay attacks depending on the configuration. An attacker who successfully exploited ...
CVE-2025-55232CRITICAL9.8Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an unauthorized attacker to ex...
CVE-2025-54261CRITICAL10ColdFusion versions 2025.3, 2023.15, 2021.21 and earlier are affected by an Improper Limitation of a Pathname to a Restr...
CVE-2025-47569CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPSwings WooCommer...
CVE-2025-32486CRITICAL9.8Weak Password Recovery Mechanism for Forgotten Password vulnerability in Hossein Material Dashboard material-dashboard.T...
CVE-2025-10183CRITICAL9.1A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthent...
CVE-2025-9994CRITICAL9.8The Amp’ed RF BT-AP 111 Bluetooth access point's HTTP admin interface does not have an authentication feature, allowing ...
CVE-2025-54236CRITICAL9.1Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an...
CVE-2025-40804CRITICAL9.3A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected applica...
CVE-2025-40795CRITICAL9.8A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC...
CVE-2025-40594CRITICAL9.8A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now