2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68716HIGH8.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo...
CVE-2025-15464HIGH7.5Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, ...
CVE-2025-14505MEDIUM5.6The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed ...
CVE-2025-68715CRITICAL9.1An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor...
CVE-2025-66916CRITICAL9.4The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression...
CVE-2025-66913CRITICAL9.8JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a...
CVE-2025-67325CRITICAL9.8Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated...
CVE-2025-65731MEDIUM6.8An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacke...
CVE-2025-65518HIGH7.5Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability e...
CVE-2025-68158HIGH8.8Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed...
CVE-2025-67825MEDIUM5.5An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information...
CVE-2025-61550MEDIUM5.4Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/Temp...
CVE-2025-61549MEDIUM6.1Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B...
CVE-2025-61548CRITICAL9.8SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo...
CVE-2025-61547MEDIUM6.8Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1...
CVE-2025-61546CRITICAL9.1There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W...
CVE-2025-61246CRITICAL9.8indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param...
CVE-2025-59470CRITICAL9This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal...
CVE-2025-59469CRITICAL9This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-59468CRITICAL9.1This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ...
CVE-2025-56425CRITICAL9.1An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto...
CVE-2025-56424HIGH7.5An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a...
CVE-2025-55125CRITICAL9.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio...
CVE-2025-50334HIGH7.5An issue in Technitium DNS Server v.13.5 allows a remote attacker to cause a denial of service via the rate-limiting com...
CVE-2025-68151HIGH7.5CoreDNS is a DNS server that chains plugins. Prior to version 1.14.0, multiple CoreDNS server implementations (gRPC, HTT...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now