2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-12420CRITICAL9.8A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersona...
CVE-2025-67147CRITICAL9.8Multiple SQL Injection vulnerabilities exist in amansuryawanshi Gym-Management-System-PHP 1.0 via the 'name', 'email', a...
CVE-2025-66802CRITICAL9.8Sourcecodester Covid-19 Contact Tracing System 1.0 is vulnerable to RCE (Remote Code Execution). The application receive...
CVE-2025-51567CRITICAL9.1A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote a...
CVE-2025-68472CRITICAL9.1MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenti...
CVE-2025-63314CRITICAL10A static password reset token in the password reset function of DDSN Interactive Acora CMS v10.7.1 allows attackers to a...
CVE-2025-46070CRITICAL9.8An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe compon...
CVE-2025-46066CRITICAL9.9An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges
CVE-2025-65552CRITICAL9.8D3D Wi-Fi Home Security System ZX-G12 v2.1.1 is vulnerable to RF replay attacks on the 433 MHz sensor communication chan...
CVE-2025-41006CRITICAL9.3Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.
CVE-2025-69270CRITICAL9.8Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux...
CVE-2025-69269CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX ...
CVE-2025-52694CRITICAL9.8Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb...
CVE-2025-15503CRITICAL9.8A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele...
CVE-2025-15502CRITICAL9.8A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ...
CVE-2025-65091CRITICAL10XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t...
CVE-2025-61686CRITICAL9.1React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version...
CVE-2025-15501CRITICAL9.8A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct...
CVE-2025-15500CRITICAL9.8A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un...
CVE-2025-15499CRITICAL9.8A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af...
CVE-2025-70161CRITICAL9.8EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe...
CVE-2025-69542CRITICAL9.8A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner...
CVE-2025-69426CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s...
CVE-2025-69425CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2...
CVE-2025-15496CRITICAL9.8A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now