2025 CVE Vulnerabilities

45,324 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-68719HIGH8.8KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 mishandle configuration management. Once any user is logged in and main...
CVE-2025-68718MEDIUM5.4KAYSUS KS-WR1200 routers with firmware 107 expose SSH and TELNET services on the LAN interface with hardcoded root crede...
CVE-2025-68717CRITICAL9.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l...
CVE-2025-68716HIGH8.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 enable the SSH service enabled by default on the LAN interface. The roo...
CVE-2025-15464HIGH7.5Exported Activity allows external applications to gain application context and directly launch Gmail with inbox access, ...
CVE-2025-14505MEDIUM5.6The ECDSA implementation of the Elliptic package generates incorrect signatures if an interim value of 'k' (as computed ...
CVE-2025-68715CRITICAL9.1An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor...
CVE-2025-66916CRITICAL9.4The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression...
CVE-2025-66913CRITICAL9.8JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a...
CVE-2025-67325CRITICAL9.8Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated...
CVE-2025-65731MEDIUM6.8An issue was discovered in D-Link Router DIR-605L (Hardware version F1; Firmware version: V6.02CN02) allowing an attacke...
CVE-2025-65518HIGH7.5Plesk Obsidian versions 8.0.1 through 18.0.73 are vulnerable to a Denial of Service (DoS) condition. The vulnerability e...
CVE-2025-68158HIGH8.8Authlib is a Python library which builds OAuth and OpenID Connect servers. In versions 1.0.0 through 1.6.5, cache-backed...
CVE-2025-67825MEDIUM5.5An issue was discovered in Nitro PDF Pro for Windows before 14.42.0.34. In certain cases, it displays signer information...
CVE-2025-61550MEDIUM5.4Cross-Site Scripting (XSS) is present on the ctl00_Content01_fieldValue parameters on the /psp/appNet/TemplateOrder/Temp...
CVE-2025-61549MEDIUM6.1Cross-Site Scripting (XSS) is present on the LoginID parameter on the /PSP/app/web/reg/reg_display.asp endpoint in edu B...
CVE-2025-61548CRITICAL9.8SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo...
CVE-2025-61547MEDIUM6.8Cross-Site Request Forgery (CSRF) is present on all functions in edu Business Solutions Print Shop Pro WebDesk version 1...
CVE-2025-61546CRITICAL9.1There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W...
CVE-2025-61246CRITICAL9.8indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param...
CVE-2025-59470CRITICAL9This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal...
CVE-2025-59469CRITICAL9This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-59468CRITICAL9.1This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ...
CVE-2025-56425CRITICAL9.1An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto...
CVE-2025-56424HIGH7.5An issue in Insiders Technologies GmbH e-invoice pro before release 1 Service Pack 2 allows a remote attacker to cause a...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now