2025 CVE Archive

This archive lists CVEs published in 2025 that have stable human-reviewed guidance or complete source-linked AI enrichment. Open a record for sourced facts, affected-product evidence, and a bounded remediation workflow.

Showing records 1–11 of 11.

  1. CVE-2025-55182Meta React Server Components Remote Code Execution VulnerabilityCRITICAL · CVSS 10 · CISA KEV · software/application · Published
  2. CVE-2025-60455CVE-2025-60455 - Modular Max Serve unsafe deserializationHIGH · CVSS 8.4 · software/application · Published
  3. CVE-2025-64446Fortinet FortiWeb Path Traversal VulnerabilityCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
  4. CVE-2025-11953CVE-2025-11953: Metro4Shell React Native CLI RCECRITICAL · CVSS 9.8 · CISA KEV · windows/system · Published
  5. CVE-2025-25257CVE-2025-25257: FortiWeb unauthenticated SQL injectionCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
  6. CVE-2025-20337Cisco Identity Services Engine Injection VulnerabilityCRITICAL · CVSS 10 · CISA KEV · software/application · Published
  7. CVE-2025-48384CVE-2025-48384: Git Submodule RCE RemediationHIGH · CVSS 8 · CISA KEV · software/application · Published
  8. CVE-2025-20281Cisco Identity Services Engine Injection VulnerabilityCRITICAL · CVSS 10 · CISA KEV · software/application · Published
  9. CVE-2025-34028Commvault Command Center Path Traversal VulnerabilityCRITICAL · CVSS 10 · CISA KEV · software/application · Published
  10. CVE-2025-3248CVE-2025-3248: Langflow Unauthenticated RCE RemediationCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published
  11. CVE-2025-2747Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel VulnerabilityCRITICAL · CVSS 9.8 · CISA KEV · software/application · Published

Browse every publication year · Search the CVE Database