2025 CVE Vulnerabilities

45,294 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-0217HIGH7.8BeyondTrust Privileged Remote Access (PRA) versions prior to 25.1 are vulnerable to a local authentication bypass. A loc...
CVE-2025-4281MEDIUM5.3A vulnerability, which was classified as problematic, was found in Shenzhen Sixun Software Sixun Shanghui Group Business...
CVE-2025-45322HIGH8.8kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in osms/Requester/CheckStatus.php via the...
CVE-2025-45321HIGH8.8kashipara Online Service Management Portal V1.0 is vulnerable to SQL Injection in /osms/Requester/Requesterchangepass.ph...
CVE-2025-45320MEDIUM5.3A Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management...
CVE-2025-45042CRITICAL9.8Tenda AC9 v15.03.05.14 was discovered to contain a command injection vulnerability via the Telnet function.
CVE-2025-28062HIGH8.1A Cross-Site Request Forgery (CSRF) vulnerability was discovered in ERPNEXT 14.82.1 and 14.74.3. The vulnerability allow...
CVE-2025-27921MEDIUM6.1A reflected cross-site scripting (XSS) vulnerability was discovered in Output Messenger before 2.0.63, where unsanitized...
CVE-2025-27920HIGH8.8Output Messenger before 2.0.63 was vulnerable to a directory traversal attack through improper file path handling. By us...
CVE-2025-26241MEDIUM6.5A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authentica...
CVE-2025-25504MEDIUM6.5An issue in the /usr/local/bin/jncs.sh script of Gefen WebFWC (In AV over IP products) v1.85h, v1.86v, and v1.70 allows ...
CVE-2025-47240Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu...
CVE-2025-4316MEDIUM4.3Improper access control in PAM feature in Devolutions Server allows a PAM user to self approve their PAM requests even i...
CVE-2025-47268MEDIUM6.5ping in iputils before 20250602 allows a denial of service (application error or incorrect data collection) via a crafte...
CVE-2025-45751MEDIUM6.1SourceCodester Web Based Pharmacy Product Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in add-admin...
CVE-2025-28168CRITICAL9.8The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs be...
CVE-2025-2545LOW2.3Vulnerability in Best Practical Solutions, LLC's Request Tracker prior to v5.0.8, where the Triple DES (3DES) cryptograp...
CVE-2025-4272HIGH7.3A vulnerability was found in Mechrevo Control Console 1.0.2.70. It has been rated as critical. Affected by this issue is...
CVE-2025-2905CRITICAL9.1Due to the improper configuration of XML parser, user-supplied XML is parsed without applying sufficient restrictions, e...
CVE-2025-4271MEDIUM6.9A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been declared as problematic. Affected by this vulnerabi...
CVE-2025-4270HIGH7.5A vulnerability was found in TOTOLINK A720R 4.1.5cu.374. It has been classified as problematic. Affected is an unknown f...
CVE-2025-4269MEDIUM5.3A vulnerability was found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This issue affects some unknown proc...
CVE-2025-4268MEDIUM6.9A vulnerability has been found in TOTOLINK A720R 4.1.5cu.374 and classified as critical. This vulnerability affects unkn...
CVE-2025-4267HIGH7.2A vulnerability, which was classified as critical, was found in SourceCodester/oretnom23 Stock Management System 1.0. Th...
CVE-2025-4266CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Notice Board System 1.0. Affected by thi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now