2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40554 | CRITICAL | 9.8 | 58.4% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that, if exploited, could... |
| CVE-2025-40553 | CRITICAL | 9.8 | 60.4% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ... |
| CVE-2025-40552 | CRITICAL | 9.8 | 49.7% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an authentication bypass vulnerability that if exploited, would ... |
| CVE-2025-40551 | CRITICAL | 9.8 | 84.1% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to an untrusted data deserialization vulnerability that could lead ... |
| CVE-2025-40536 | CRITICAL | 9.8 | 81.6% | Jan 28, 2026 | SolarWinds Web Help Desk was found to be susceptible to a security control bypass vulnerability that if exploited, could... |
| CVE-2025-21589 | CRITICAL | 9.8 | 1.4% | Jan 27, 2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability in Juniper Networks Session Smart Router may a... |
| CVE-2025-14988 | CRITICAL | 10 | 0.4% | Jan 27, 2026 | A security issue has been identified in ibaPDA that could allow unauthorized actions on the file system under certain co... |
| CVE-2025-69564 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExAddNewUser.php via the Name, Addres... |
| CVE-2025-69563 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /ExLogin.php via the Password paramete... |
| CVE-2025-69562 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para... |
| CVE-2025-69559 | CRITICAL | 9.8 | 0.5% | Jan 27, 2026 | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. |
| CVE-2025-69565 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. |
| CVE-2025-68670 | CRITICAL | 9.8 | 1.3% | Jan 27, 2026 | xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi... |
| CVE-2025-70982 | CRITICAL | 9.9 | 0.3% | Jan 26, 2026 | Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ... |
| CVE-2025-59108 | CRITICAL | 9.2 | 0.4% | Jan 26, 2026 | By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p... |
| CVE-2025-59103 | CRITICAL | 9.2 | 0.4% | Jan 26, 2026 | The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis... |
| CVE-2025-59097 | CRITICAL | 9.3 | 0.5% | Jan 26, 2026 | The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done... |
| CVE-2025-59091 | CRITICAL | 9.3 | 0.8% | Jan 26, 2026 | Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn... |
| CVE-2025-59090 | CRITICAL | 9.3 | 1.0% | Jan 26, 2026 | On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen... |
| CVE-2025-13374 | CRITICAL | 9.8 | 1.1% | Jan 24, 2026 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-13952 | CRITICAL | 9.8 | 0.4% | Jan 24, 2026 | A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr... |
| CVE-2025-70457 | CRITICAL | 9.8 | 0.8% | Jan 23, 2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up... |
| CVE-2025-52025 | CRITICAL | 9.4 | 0.3% | Jan 23, 2026 | An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen... |
| CVE-2025-52024 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin... |
| CVE-2025-70985 | CRITICAL | 9.1 | 0.4% | Jan 23, 2026 | Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now