2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69562 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to SQL Injection in /insertmessage.php via the userid para... |
| CVE-2025-69559 | CRITICAL | 9.8 | 0.5% | Jan 27, 2026 | code-projects Computer Book Store 1.0 is vulnerable to File Upload in admin_add.php. |
| CVE-2025-69565 | CRITICAL | 9.8 | 0.4% | Jan 27, 2026 | code-projects Mobile Shop Management System 1.0 is vulnerable to File Upload in /ExAddProduct.php. |
| CVE-2025-68670 | CRITICAL | 9.8 | 1.3% | Jan 27, 2026 | xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerabi... |
| CVE-2025-70982 | CRITICAL | 9.9 | 0.3% | Jan 26, 2026 | Incorrect access control in the importUser function of SpringBlade v4.5.0 allows attackers with low-level privileges to ... |
| CVE-2025-59108 | CRITICAL | 9.2 | 0.4% | Jan 26, 2026 | By default, the password for the Access Manager's web interface, is set to 'admin'. In the tested version changing the p... |
| CVE-2025-59103 | CRITICAL | 9.2 | 0.4% | Jan 26, 2026 | The Access Manager 92xx in hardware revision K7 is based on Linux instead of Windows CE embedded in older hardware revis... |
| CVE-2025-59097 | CRITICAL | 9.3 | 0.5% | Jan 26, 2026 | The exos 9300 application can be used to configure Access Managers (e.g. 92xx, 9230 and 9290). The configuration is done... |
| CVE-2025-59091 | CRITICAL | 9.3 | 0.8% | Jan 26, 2026 | Multiple hardcoded credentials have been identified, which are allowed to sign-in to the exos 9300 datapoint server runn... |
| CVE-2025-59090 | CRITICAL | 9.3 | 1.0% | Jan 26, 2026 | On the exos 9300 server, a SOAP API is reachable on port 8002. This API does not require any authentication prior to sen... |
| CVE-2025-13374 | CRITICAL | 9.8 | 1.1% | Jan 24, 2026 | The Kalrav AI Agent plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in ... |
| CVE-2025-13952 | CRITICAL | 9.8 | 0.4% | Jan 24, 2026 | A web page that contains unusual GPU shader code is loaded from the Internet into the GPU compiler process triggers a wr... |
| CVE-2025-70457 | CRITICAL | 9.8 | 0.8% | Jan 23, 2026 | A Remote Code Execution (RCE) vulnerability exists in Sourcecodester Modern Image Gallery App v1.0 within the gallery/up... |
| CVE-2025-52025 | CRITICAL | 9.4 | 0.3% | Jan 23, 2026 | An SQL Injection vulnerability exists in the GetServiceByRestaurantID endpoint of the Aptsys gemscms POS Platform backen... |
| CVE-2025-52024 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | A vulnerability exists in the Aptsys POS Platform Web Services module thru 2025-05-28, which exposes internal API testin... |
| CVE-2025-70985 | CRITICAL | 9.1 | 0.4% | Jan 23, 2026 | Incorrect access control in the update function of RuoYi v4.8.2 allows unauthorized attackers to arbitrarily modify data... |
| CVE-2025-70983 | CRITICAL | 9.9 | 0.4% | Jan 23, 2026 | Incorrect access control in the authRoutes function of SpringBlade v4.5.0 allows attackers with low-level privileges to ... |
| CVE-2025-67229 | CRITICAL | 9.8 | 0.3% | Jan 23, 2026 | An improper certificate validation vulnerability exists in ToDesktop Builder v0.32.1 This vulnerability allows an unauth... |
| CVE-2025-66719 | CRITICAL | 9.1 | 0.3% | Jan 23, 2026 | An issue was discovered in Free5gc NRF 1.4.0. In the access-token generation logic of free5GC, the AccessTokenScopeCheck... |
| CVE-2025-4320 | CRITICAL | 10 | 0.5% | Jan 23, 2026 | Authentication Bypass by Primary Weakness, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Bire... |
| CVE-2025-4319 | CRITICAL | 9.4 | 0.4% | Jan 23, 2026 | Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulne... |
| CVE-2025-15063 | CRITICAL | 9.8 | 2.1% | Jan 23, 2026 | Ollama MCP Server execAsync Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote atta... |
| CVE-2025-15061 | CRITICAL | 9.8 | 2.1% | Jan 23, 2026 | Framelink Figma MCP Server fetchWithRetry Command Injection Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2025-55705 | CRITICAL | 9.8 | 0.3% | Jan 22, 2026 | This vulnerability occurs when the system permits multiple simultaneous connections to the backend using the same charg... |
| CVE-2025-54816 | CRITICAL | 9.8 | 0.4% | Jan 22, 2026 | This vulnerability occurs when a WebSocket endpoint does not enforce proper authentication mechanisms, allowing unautho... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now