2025 CVE Vulnerabilities

45,322 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-70841HIGH7.5Dokans Multi-Tenancy Based eCommerce Platform SaaS 3.9.2 allows unauthenticated remote attackers to obtain sensitive app...
CVE-2025-70758HIGH7.5chetans9 core-php-admin-panel through commit a94a780d6 contains an authentication bypass vulnerability in includes/auth_...
CVE-2025-70560HIGH8.4Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application us...
CVE-2025-70559MEDIUM6.5pdfminer.six before 20251230 contains an insecure deserialization vulnerability in the CMap loading mechanism. The libra...
CVE-2025-70311MEDIUM6.5JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 paramet...
CVE-2025-69983CRITICAL9.8FUXA v1.2.7 allows Remote Code Execution (RCE) via the project import functionality. The application does not properly s...
CVE-2025-69981CRITICAL9.8FUXA v1.2.7 contains an Unrestricted File Upload vulnerability in the `/api/upload` API endpoint. The endpoint lacks aut...
CVE-2025-69971CRITICAL9.8FUXA v1.2.7 contains a hard-coded credential vulnerability in server/api/jwt-helper.js. The application uses a hard-code...
CVE-2025-69970CRITICAL9.3FUXA v1.2.7 contains an insecure default configuration vulnerability in server/settings.default.js. The 'secureEnabled' ...
CVE-2025-69875HIGH7.8A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient val...
CVE-2025-69848MEDIUM5.4NetBox is an open-source infrastructure resource modeling and IP address management platform. A reflected cross-site scr...
CVE-2025-69431MEDIUM6.1The ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB dri...
CVE-2025-69430MEDIUM6.1An Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or...
CVE-2025-69429MEDIUM6.1The ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploi...
CVE-2025-67189MEDIUM6.5A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The...
CVE-2025-67188CRITICAL9.8A buffer overflow vulnerability exists in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The issue resides in the setRadvdCfg ...
CVE-2025-67187CRITICAL9.8A stack-based buffer overflow vulnerability was identified in TOTOLINK A950RG V4.1.2cu.5204_B20210112. The flaw exists i...
CVE-2025-67186CRITICAL9.8TOTOLINK A950RG V4.1.2cu.5204_B20210112 contains a buffer overflow vulnerability in the setUrlFilterRules interface of /...
CVE-2025-66374HIGH7.8CyberArk Endpoint Privilege Manager Agent through 25.10.0 allows a local user to achieve privilege escalation through po...
CVE-2025-65924MEDIUM4.1ERPNext thru 15.88.1 does not sanitize or remove certain HTML tags specifically `<a>` hyperlinks in fields that are inte...
CVE-2025-65923MEDIUM5.4A Stored Cross-Site Scripting (XSS) vulnerability was discovered within the CSV import mechanism of ERPNext thru 15.88.1...
CVE-2025-65875CRITICAL9.8An arbitrary file upload vulnerability in the AddFont() function of FPDF v1.86 and earlier allows attackers to execute a...
CVE-2025-63624CRITICAL9.8SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows...
CVE-2025-63372MEDIUM4.3Articentgroup Zip Rar Extractor Tool 1.345.93.0 is vulnerable to Directory Traversal. The vulnerability resides in the Z...
CVE-2025-62599HIGH7.5eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now