2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-68716 | HIGH | 8.4 | 0.2% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo... |
| CVE-2025-15464 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, ... |
| CVE-2025-14505 | MEDIUM | 5.6 | 0.2% | Jan 8, 2026 | The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed ... |
| CVE-2025-68715 | CRITICAL | 9.1 | 0.6% | Jan 8, 2026 | An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor... |
| CVE-2025-66916 | CRITICAL | 9.4 | 0.6% | Jan 8, 2026 | The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression... |
| CVE-2025-66913 | CRITICAL | 9.8 | 0.9% | Jan 8, 2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a... |
| CVE-2025-67325 | CRITICAL | 9.8 | 0.8% | Jan 8, 2026 | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated... |
| CVE-2025-65731 | MEDIUM | 6.8 | 0.4% | Jan 8, 2026 | An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacke... |
| CVE-2025-65518 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability e... |
| CVE-2025-68158 | HIGH | 8.8 | 0.2% | Jan 8, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed... |
| CVE-2025-67825 | MEDIUM | 5.5 | 0.1% | Jan 8, 2026 | An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information... |
| CVE-2025-61550 | MEDIUM | 5.4 | 0.2% | Jan 8, 2026 | Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/Temp... |
| CVE-2025-61549 | MEDIUM | 6.1 | 0.2% | Jan 8, 2026 | Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B... |
| CVE-2025-61548 | CRITICAL | 9.8 | 0.5% | Jan 8, 2026 | SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo... |
| CVE-2025-61547 | MEDIUM | 6.8 | 0.1% | Jan 8, 2026 | Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1... |
| CVE-2025-61546 | CRITICAL | 9.1 | 0.5% | Jan 8, 2026 | There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W... |
| CVE-2025-61246 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param... |
| CVE-2025-59470 | CRITICAL | 9 | 1.5% | Jan 8, 2026 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal... |
| CVE-2025-59469 | CRITICAL | 9 | 0.6% | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to write files as root. |
| CVE-2025-59468 | CRITICAL | 9.1 | 1.1% | Jan 8, 2026 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ... |
| CVE-2025-56425 | CRITICAL | 9.1 | 0.6% | Jan 8, 2026 | An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto... |
| CVE-2025-56424 | HIGH | 7.5 | 0.5% | Jan 8, 2026 | An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a... |
| CVE-2025-55125 | CRITICAL | 9.8 | 0.8% | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio... |
| CVE-2025-50334 | HIGH | 7.5 | 1.0% | Jan 8, 2026 | An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com... |
| CVE-2025-68151 | HIGH | 7.5 | 0.4% | Jan 8, 2026 | CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now