2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27225 | HIGH | 7.5 | 17.6% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unau... |
| CVE-2025-27223 | HIGH | 7.5 | 2.1% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints s... |
| CVE-2025-27222 | HIGH | 8.6 | 1.9% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, t... |
| CVE-2025-12295 | HIGH | 8.1 | 0.4% | Oct 27, 2025 | A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo... |
| CVE-2025-61247 | HIGH | 8.2 | 0.2% | Oct 27, 2025 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php. |
| CVE-2025-60425 | HIGH | 8.6 | 0.9% | Oct 27, 2025 | Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authenticati... |
| CVE-2025-60424 | HIGH | 7.6 | 0.7% | Oct 27, 2025 | A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to byp... |
| CVE-2025-34133 | HIGH | 7 | 0.2% | Oct 27, 2025 | Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API a... |
| CVE-2025-61482 | HIGH | 7.2 | 0.1% | Oct 27, 2025 | Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local a... |
| CVE-2025-52268 | HIGH | 7.5 | 0.3% | Oct 27, 2025 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to for... |
| CVE-2025-52264 | HIGH | 8 | 0.3% | Oct 27, 2025 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at down... |
| CVE-2025-12288 | HIGH | 8.8 | 0.4% | Oct 27, 2025 | A vulnerability was detected in Bdtask Pharmacy Management System up to 9.4. Affected is an unknown function of the file... |
| CVE-2025-12287 | HIGH | 7.2 | 0.4% | Oct 27, 2025 | A security vulnerability has been detected in Bdtask Wholesale Inventory Control and Inventory Management System up to 2... |
| CVE-2025-9164 | HIGH | 8.8 | 0.1% | Oct 27, 2025 | Docker Desktop Installer.exe is vulnerable to DLL hijacking due to insecure DLL search order. The installer searches for... |
| CVE-2025-52263 | HIGH | 8 | 0.2% | Oct 27, 2025 | An issue in the Web Configuration module of Startcharge Artemis AC Charger 7-22 kW v1.0.4 allows authenticated network-a... |
| CVE-2025-12286 | HIGH | 7.3 | 0.2% | Oct 27, 2025 | A weakness has been identified in VeePN up to 1.6.2. This affects an unknown function of the file C:\Program Files (x86)... |
| CVE-2025-12283 | HIGH | 8.1 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in code-projects Client Details System 1.0. The impacted element is an unknown funct... |
| CVE-2025-41068 | HIGH | 7.5 | 0.3% | Oct 27, 2025 | Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause ... |
| CVE-2025-41067 | HIGH | 7.5 | 0.4% | Oct 27, 2025 | Reachable Assertion vulnerability in Open5GS up to version 2.7.6 allows attackers with connectivity to the NRF to cause ... |
| CVE-2025-12277 | HIGH | 7.3 | 0.3% | Oct 27, 2025 | A flaw has been found in Abdullah-Hasan-Sajjad Online-School up to f09dda77b4c29aa083ff57f4b1eb991b98b68883. This affect... |
| CVE-2025-12276 | HIGH | 7.5 | 0.4% | Oct 27, 2025 | A vulnerability was detected in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Affected by this issue is som... |
| CVE-2025-12274 | HIGH | 8.8 | 0.6% | Oct 27, 2025 | A security vulnerability has been detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromP2p... |
| CVE-2025-12270 | HIGH | 7.5 | 0.4% | Oct 27, 2025 | A vulnerability was determined in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. The impacted element is an ... |
| CVE-2025-11955 | HIGH | 8.2 | 0.3% | Oct 27, 2025 | Incorrect validation of OCSP certificates vulnerability in TheGreenBow VPN, versions 7.5 and 7.6. During the IKEv2 authe... |
| CVE-2025-59463 | HIGH | 7.5 | 0.4% | Oct 27, 2025 | An attacker may cause chunk-size mismatches that block file transfers and prevent subsequent transfers. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now