2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63624 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | SQL Injection vulnerability in Shandong Kede Electronics Co., Ltd IoT smart water meter monitoring platform v.1.0 allows... |
| CVE-2025-61506 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | An issue was discovered in MediaCrush thru 1.0.1 allowing remote unauthenticated attackers to upload arbitrary files of ... |
| CVE-2025-57529 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | YouDataSum CPAS Audit Management System <=v4.9 is vulnerable to SQL Injection in /cpasList/findArchiveReportByDah due to... |
| CVE-2025-52626 | CRITICAL | 9.8 | 0.6% | Feb 3, 2026 | A Potential Command Injection vulnerability in HCL AION. An This can allow unintended command execution, potentially ... |
| CVE-2025-5319 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Emit Informatics a... |
| CVE-2025-67856 | CRITICAL | 9.8 | 0.3% | Feb 3, 2026 | A flaw was found in Moodle. An authorization logic flaw, specifically due to incomplete role checks during the badge awa... |
| CVE-2025-67484 | CRITICAL | 9.8 | 0.4% | Feb 3, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiFor... |
| CVE-2025-66480 | CRITICAL | 9.8 | 1.4% | Feb 2, 2026 | Wildfire IM is an instant messaging and real-time audio/video solution. Prior to 1.4.3, a critical vulnerability exists ... |
| CVE-2025-8587 | CRITICAL | 9.8 | 0.3% | Feb 2, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AKCE Software Tech... |
| CVE-2025-15030 | CRITICAL | 9.8 | 0.5% | Feb 2, 2026 | The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few u... |
| CVE-2025-24293 | CRITICAL | 9.2 | 2.4% | Jan 30, 2026 | # Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of pote... |
| CVE-2025-51958 | CRITICAL | 9.8 | 0.6% | Jan 30, 2026 | aelsantex runcommand 2014-04-01, a plugin for DokuWiki, allows unauthenticated attackers to execute arbitrary system com... |
| CVE-2025-7964 | CRITICAL | 9.2 | 0.3% | Jan 30, 2026 | After receiving a malformed 802.15.4 MAC Data Request the Zigbee Coordinator sends a ‘network leave’ request to Zigb... |
| CVE-2025-26385 | CRITICAL | 9.5 | 1.4% | Jan 30, 2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Com... |
| CVE-2025-69929 | CRITICAL | 9.8 | 0.4% | Jan 29, 2026 | An issue in N3uron Web User Interface v.1.21.7-240207.1047 allows a remote attacker to escalate privileges via the passw... |
| CVE-2025-7714 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Global Interactive... |
| CVE-2025-7013 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in QR Menu Pro Smart Menu Systems Menu Panel allows Explo... |
| CVE-2025-7016 | CRITICAL | 9.8 | 0.3% | Jan 29, 2026 | Improper Access Control vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Aut... |
| CVE-2025-7015 | CRITICAL | 9.8 | 0.2% | Jan 29, 2026 | Session Fixation vulnerability in Akın Software Computer Import Export Industry and Trade Ltd. QR Menu allows Session Fi... |
| CVE-2025-68662 | CRITICAL | 9.9 | 0.3% | Jan 28, 2026 | Discourse is an open source discussion platform. In versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0, a hostn... |
| CVE-2025-69602 | CRITICAL | 9.1 | 0.3% | Jan 28, 2026 | A session fixation vulnerability exists in 66biolinks v62.0.0 by AltumCode, where the application does not regenerate th... |
| CVE-2025-57795 | CRITICAL | 9.9 | 0.5% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.13 contain an authenticated remote file download vulnerability in a web service c... |
| CVE-2025-57794 | CRITICAL | 9.1 | 0.5% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.9 contain an authenticated unrestricted file upload vulnerability in the administ... |
| CVE-2025-57792 | CRITICAL | 10 | 0.4% | Jan 28, 2026 | Explorance Blue versions prior to 8.14.9 contain a SQL injection vulnerability caused by insufficient validation of user... |
| CVE-2025-61140 | CRITICAL | 9.8 | 0.4% | Jan 28, 2026 | The value function in jsonpath 1.1.1 lib/index.js is vulnerable to Prototype Pollution. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now