2025 CVE Vulnerabilities

45,145 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-27225HIGH7.5TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unau...
CVE-2025-27223HIGH7.5TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints s...
CVE-2025-27222HIGH8.6TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, t...
CVE-2025-12295HIGH8.1A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo...
CVE-2025-61247HIGH8.2indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php.
CVE-2025-60425HIGH8.6Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authenticati...
CVE-2025-60424HIGH7.6A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to byp...
CVE-2025-34133HIGH7Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API a...
CVE-2025-61482HIGH7.2Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local a...
CVE-2025-52268HIGH7.5StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to for...
CVE-2025-52264HIGH8StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at down...
CVE-2025-12288HIGH8.8A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file...
CVE-2025-12287HIGH7.2A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 2...
CVE-2025-9164HIGH8.8Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for...
CVE-2025-52263HIGH8An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-a...
CVE-2025-12286HIGH7.3A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)...
CVE-2025-12283HIGH8.1A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown funct...
CVE-2025-41068HIGH7.5Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause ...
CVE-2025-41067HIGH7.5Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause ...
CVE-2025-12277HIGH7.3A flaw has been found in Abdullah-Hasan-Sajjad Online-School up to f09dda77b4c29aa083ff57f4b1eb991b98b68883. This affect...
CVE-2025-12276HIGH7.5A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is som...
CVE-2025-12274HIGH8.8A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2p...
CVE-2025-12270HIGH7.5A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an ...
CVE-2025-11955HIGH8.2Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authe...
CVE-2025-59463HIGH7.5An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now