2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41769 | CRITICAL | 9.8 | — | Aug 12, 2026 | The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A... |
| CVE-2025-31114 | CRITICAL | 9.3 | — | Aug 11, 2026 | Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex... |
| CVE-2025-15681 | CRITICAL | 9.2 | — | Aug 10, 2026 | TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic... |
| CVE-2025-13294 | CRITICAL | 9.3 | — | Aug 10, 2026 | An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ... |
| CVE-2025-13293 | CRITICAL | 9.3 | — | Aug 10, 2026 | A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack... |
| CVE-2025-14561 | CRITICAL | 9 | 0.4% | Aug 6, 2026 | In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o... |
| CVE-2025-15039 | CRITICAL | 9.4 | 0.4% | Aug 6, 2026 | The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require... |
| CVE-2025-63823 | CRITICAL | 9.8 | 0.3% | Aug 5, 2026 | My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote ... |
| CVE-2025-29296 | CRITICAL | 9.8 | — | Aug 4, 2026 | H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V... |
| CVE-2025-71401 | CRITICAL | 9.3 | 0.3% | Aug 2, 2026 | better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B... |
| CVE-2025-69948 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. |
| CVE-2025-69946 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr... |
| CVE-2025-67649 | CRITICAL | 9.3 | — | Jul 31, 2026 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input ... |
| CVE-2025-69947 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. |
| CVE-2025-69941 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. |
| CVE-2025-69938 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. |
| CVE-2025-69937 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete... |
| CVE-2025-69936 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. |
| CVE-2025-69935 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th... |
| CVE-2025-69934 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. |
| CVE-2025-69933 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. |
| CVE-2025-69931 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. |
| CVE-2025-69930 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. |
| CVE-2025-65336 | CRITICAL | 9.8 | 0.2% | Jul 30, 2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. |
| CVE-2025-69943 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now