2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12420 | CRITICAL | 9.8 | 45.5% | Jan 12, 2026 | A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona... |
| CVE-2025-67147 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a... |
| CVE-2025-66802 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive... |
| CVE-2025-51567 | CRITICAL | 9.1 | 0.4% | Jan 12, 2026 | A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a... |
| CVE-2025-68472 | CRITICAL | 9.1 | 19.2% | Jan 12, 2026 | MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti... |
| CVE-2025-63314 | CRITICAL | 10 | 0.3% | Jan 12, 2026 | A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a... |
| CVE-2025-46070 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon... |
| CVE-2025-46066 | CRITICAL | 9.9 | 0.3% | Jan 12, 2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges |
| CVE-2025-65552 | CRITICAL | 9.8 | 0.4% | Jan 12, 2026 | D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan... |
| CVE-2025-41006 | CRITICAL | 9.3 | 0.3% | Jan 12, 2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. |
| CVE-2025-69270 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux... |
| CVE-2025-69269 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX ... |
| CVE-2025-52694 | CRITICAL | 9.8 | 37.9% | Jan 12, 2026 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb... |
| CVE-2025-15503 | CRITICAL | 9.8 | 1.9% | Jan 10, 2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele... |
| CVE-2025-15502 | CRITICAL | 9.8 | 5.6% | Jan 10, 2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ... |
| CVE-2025-65091 | CRITICAL | 10 | 0.3% | Jan 10, 2026 | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t... |
| CVE-2025-61686 | CRITICAL | 9.1 | 16.1% | Jan 10, 2026 | React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version... |
| CVE-2025-15501 | CRITICAL | 9.8 | 6.4% | Jan 9, 2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct... |
| CVE-2025-15500 | CRITICAL | 9.8 | 5.6% | Jan 9, 2026 | A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un... |
| CVE-2025-15499 | CRITICAL | 9.8 | 5.3% | Jan 9, 2026 | A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af... |
| CVE-2025-70161 | CRITICAL | 9.8 | 24.1% | Jan 9, 2026 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe... |
| CVE-2025-69542 | CRITICAL | 9.8 | 8.4% | Jan 9, 2026 | A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner... |
| CVE-2025-69426 | CRITICAL | 10 | 0.4% | Jan 9, 2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s... |
| CVE-2025-69425 | CRITICAL | 10 | 0.7% | Jan 9, 2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2... |
| CVE-2025-15496 | CRITICAL | 9.8 | 0.3% | Jan 9, 2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now