2025 CVE Vulnerabilities

45,277 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40666CRITICAL9.8Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a...
CVE-2025-40665CRITICAL9.8Time-based blind SQL injection vulnerabilities in TCMAN's GIM v11. These allow an attacker to retrieve, create, update a...
CVE-2025-40664CRITICAL9.1Missing authentication vulnerability in TCMAN GIM v11. This allows an unauthenticated attacker to access the resources /...
CVE-2025-40663MEDIUM5.1Stored Cross-Site Scripting (XSS) vulnerability in i2A-Cronos version 23.02.01.17, from i2A. It allows an authenticated ...
CVE-2025-40653MEDIUM6.9User enumeration vulnerability in M3M Printer Server Web. This issue occurs during user authentication, where a differen...
CVE-2025-40652MEDIUM5.3Stored Cross-Site Scripting (XSS) vulnerability in the CoverManager booking software. This allows an attacker to inject ...
CVE-2025-40650HIGH8.7Insecure Direct Object Reference (IDOR) vulnerability in Clickedu. This vulnerability could allow an attacker to retriev...
CVE-2025-5184HIGH7.5A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. It has been classified ...
CVE-2025-5183MEDIUM4.7A vulnerability was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as proble...
CVE-2025-5182HIGH7.5A vulnerability has been found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1 and classified as c...
CVE-2025-5181MEDIUM4.1A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platfor...
CVE-2025-5180HIGH7.3A vulnerability, which was classified as critical, has been found in Wondershare Filmora 14.5.16. Affected by this issue...
CVE-2025-5179LOW3.4A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by ...
CVE-2025-5178CRITICAL9.8A vulnerability classified as critical has been found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected i...
CVE-2025-5177MEDIUM4.7A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This...
CVE-2025-4057MEDIUM5.5A flaw was found in ActiveMQ Artemis. The password generated by activemq-artemis-operator does not regenerate between se...
CVE-2025-4053MEDIUM6.8The data stored in Be-Tech Mifare Classic card is stored in cleartext. An attacker having access to a Be-Tech hotel gues...
CVE-2025-40672HIGH8.5A Privilege Escalation vulnerability has been found in Panloader component v3.24.0.0 by Espiral MS Group. This vulnerabi...
CVE-2025-40671CRITICAL9.3SQL injection vulnerability in AES Multimedia's Gestnet v1.07. This vulnerability allows an attacker to retrieve, create...
CVE-2025-35003CRITICAL9.8Improper Restriction of Operations within the Bounds of a Memory Buffer and Stack-based Buffer Overflow vulnerabilities ...
CVE-2025-41655HIGH7.5An unauthenticated remote attacker can access a URL which causes the device to reboot.
CVE-2025-41654HIGH8.2An unauthenticated remote attacker can access information about running processes via the SNMP protocol. The amount of r...
CVE-2025-1985MEDIUM6.1Due to improper neutralization of input during web page generation (XSS) an unauthenticated remote attacker can inject H...
CVE-2025-5176CRITICAL9.1A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been declared as critical. This...
CVE-2025-5175MEDIUM5.5A vulnerability was found in erdogant pypickle up to 1.1.5. It has been classified as critical. This affects the functio...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now