2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-30410 | CRITICAL | 9.8 | 0.6% | Feb 20, 2026 | Sensitive data disclosure and manipulation due to missing authentication. The following products are affected: Acronis C... |
| CVE-2025-67305 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | In RUCKUS Network Director (RND) < 4.5.0.56, the OVA appliance contains hardcoded SSH keys for the postgres user. These ... |
| CVE-2025-67304 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | In Ruckus Network Director (RND) < 4.5.0.54, the OVA appliance contains hardcoded credentials for the ruckus PostgreSQL ... |
| CVE-2025-71243 | CRITICAL | 9.8 | 5.1% | Feb 19, 2026 | The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex... |
| CVE-2025-55853 | CRITICAL | 9.1 | 0.4% | Feb 19, 2026 | SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not... |
| CVE-2025-9953 | CRITICAL | 9.8 | 0.3% | Feb 19, 2026 | Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd.... |
| CVE-2025-8350 | CRITICAL | 9.8 | 0.5% | Feb 19, 2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern... |
| CVE-2025-15559 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server... |
| CVE-2025-15586 | CRITICAL | 10 | 0.4% | Feb 19, 2026 | OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic... |
| CVE-2025-13851 | CRITICAL | 9.8 | 0.3% | Feb 19, 2026 | The Buyent Classified plugin for WordPress (bundled with Buyent theme) is vulnerable to privilege escalation via user re... |
| CVE-2025-13563 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The Lizza LMS Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3... |
| CVE-2025-12882 | CRITICAL | 9.8 | 0.4% | Feb 19, 2026 | The Clasifico Listing plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0. ... |
| CVE-2025-70152 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management... |
| CVE-2025-70150 | CRITICAL | 9.8 | 0.6% | Feb 18, 2026 | CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al... |
| CVE-2025-14009 | CRITICAL | 10 | 0.8% | Feb 18, 2026 | A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f... |
| CVE-2025-70149 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame... |
| CVE-2025-70146 | CRITICAL | 9.1 | 0.5% | Feb 18, 2026 | Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera... |
| CVE-2025-70141 | CRITICAL | 9.4 | 0.5% | Feb 18, 2026 | SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp... |
| CVE-2025-70998 | CRITICAL | 9.8 | 0.4% | Feb 18, 2026 | UTT HiPER 810 / nv810v4 router firmware v1.5.0-140603 was discovered to contain insecure default credentials for the tel... |
| CVE-2025-65791 | CRITICAL | 9.8 | 1.6% | Feb 18, 2026 | ZoneMinder v1.36.34 is vulnerable to Command Injection in web/views/image.php. The application passes unsanitized user i... |
| CVE-2025-15579 | CRITICAL | 9.5 | 0.3% | Feb 18, 2026 | Deserialization of Untrusted Data vulnerability in OpenText™ Directory Services allows Object Injection. The vulnerabi... |
| CVE-2025-33089 | CRITICAL | 9.8 | 0.2% | Feb 17, 2026 | IBM Concert 1.0.0 through 2.1.0 could allow a remote attacker to obtain sensitive information or perform unauthorized ac... |
| CVE-2025-66614 | CRITICAL | 9.1 | 0.2% | Feb 17, 2026 | Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-... |
| CVE-2025-59793 | CRITICAL | 9.9 | 1.0% | Feb 17, 2026 | Rocket TRUfusion Enterprise through 7.10.5 exposes the endpoint at /axis2/services/WsPortalV6UpDwAxis2Impl to authentica... |
| CVE-2025-70830 | CRITICAL | 9.9 | 1.0% | Feb 17, 2026 | A Server-Side Template Injection (SSTI) vulnerability in the Freemarker template engine of Datart v1.0.0-rc.3 allows aut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now