2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-41769CRITICAL9.8The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. A...
CVE-2025-31114CRITICAL9.3Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code ex...
CVE-2025-15681CRITICAL9.2TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authentic...
CVE-2025-13294CRITICAL9.3An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP ...
CVE-2025-13293CRITICAL9.3A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attack...
CVE-2025-14561CRITICAL9In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in o...
CVE-2025-15039CRITICAL9.4The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all require...
CVE-2025-63823CRITICAL9.8My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote ...
CVE-2025-29296CRITICAL9.8H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V...
CVE-2025-71401CRITICAL9.3better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., B...
CVE-2025-69948CRITICAL9.8SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.
CVE-2025-69946CRITICAL9.8SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr...
CVE-2025-67649CRITICAL9.3A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input ...
CVE-2025-69947CRITICAL9.8SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
CVE-2025-69941CRITICAL9.8SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
CVE-2025-69938CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
CVE-2025-69937CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete...
CVE-2025-69936CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CVE-2025-69935CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th...
CVE-2025-69934CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
CVE-2025-69933CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
CVE-2025-69931CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
CVE-2025-69930CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
CVE-2025-65336CRITICAL9.8Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.
CVE-2025-69943CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now