2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61686CRITICAL9.1React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version...
CVE-2025-59057HIGH7.6React Router is a router for React. In @remix-run/react versions 1.15.0 through 2.17.0. and react-router versions 7.0.0 ...
CVE-2025-15501CRITICAL9.8A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct...
CVE-2025-62487LOW3.5On October 1, 2025, Palantir discovered that images uploaded through the Dossier front-end app were not being marked cor...
CVE-2025-46299MEDIUM4.3A memory initialization issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 ...
CVE-2025-46298MEDIUM6.5The issue was addressed with improved memory handling. This issue is fixed in Safari 26.2, iOS 26.2 and iPadOS 26.2, mac...
CVE-2025-46297MEDIUM5.5A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26.2. An app may be a...
CVE-2025-46286MEDIUM4.3A logic issue was addressed with improved validation. This issue is fixed in iOS 26.2 and iPadOS 26.2. Restoring from a ...
CVE-2025-15500CRITICAL9.8A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un...
CVE-2025-15499CRITICAL9.8A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af...
CVE-2025-60538MEDIUM6.5A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a bru...
CVE-2025-51626MEDIUM6.5SQL injection vulnerability in pss.sale.com 1.0 via the id parameter to the userfiles/php/cancel_order.php endpoint.
CVE-2025-67811MEDIUM6.5Area9 Rhapsode 1.47.3 allows SQL Injection via multiple API endpoints accessible to authenticated users. Insufficient in...
CVE-2025-67810MEDIUM6.5In Area9 Rhapsode 1.47.3, an authenticated attacker can exploit the operation, url, and filename parameters via POST req...
CVE-2025-66715MEDIUM6.5A DLL hijacking vulnerability in Axtion ODISSAAS ODIS v1.8.4 allows attackers to execute arbitrary code via a crafted DL...
CVE-2025-67070HIGH8.2A vulnerability exists in Intelbras CFTV IP NVD 9032 R Ftd V2.800.00IB00C.0.T, which allows an unauthenticated attacker ...
CVE-2025-70161CRITICAL9.8EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe...
CVE-2025-69542CRITICAL9.8A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner...
CVE-2025-69426CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s...
CVE-2025-69425CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2...
CVE-2025-67004MEDIUM6.5** Disputed ** An Information Disclosure vulnerability in CouchCMS 2.4 allow an Admin user to read arbitrary files via t...
CVE-2025-66744HIGH7.5In Yonyou YonBIP v3 and before, the LoginWithV8 interface in the series data application service system is vulnerable to...
CVE-2025-46645HIGH7.2Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.4....
CVE-2025-15496CRITICAL9.8A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/...
CVE-2025-15495HIGH7.2A vulnerability was found in BiggiDroid Simple PHP CMS 1.0. This impacts an unknown function of the file /admin/editsite...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now