2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-62487LOW3.5On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor...
CVE-2025-46299MEDIUM4.3A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 ...
CVE-2025-46298MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac...
CVE-2025-46297MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a...
CVE-2025-46286MEDIUM4.3A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a ...
CVE-2025-15500CRITICAL9.8A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un...
CVE-2025-15499CRITICAL9.8A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af...
CVE-2025-60538MEDIUM6.5A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a bru...
CVE-2025-51626MEDIUM6.5SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.
CVE-2025-67811MEDIUM6.5Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in...
CVE-2025-67810MEDIUM6.5In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST req...
CVE-2025-66715MEDIUM6.5A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DL...
CVE-2025-67070HIGH8.2A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker ...
CVE-2025-70161CRITICAL9.8EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe...
CVE-2025-69542CRITICAL9.8A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner...
CVE-2025-69426CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s...
CVE-2025-69425CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2...
CVE-2025-67004MEDIUM6.5** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t...
CVE-2025-66744HIGH7.5In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to...
CVE-2025-46645HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-15496CRITICAL9.8A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/...
CVE-2025-15495HIGH7.2A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite...
CVE-2025-15494HIGH8.8A vulnerability has been found in RainyGao DocSys up to 2.02.37. This affects an unknown function of the file com/DocSys...
CVE-2025-15493CRITICAL9.8A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/...
CVE-2025-15035HIGH7.3Improper Input Validation vulnerability in TP-Link Archer AXE75 v1.6 (vpn modules) allows an authenticated adjacent atta...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now