2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15493 | CRITICAL | 9.8 | 0.4% | Jan 9, 2026 | A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/... |
| CVE-2025-14598 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites.... |
| CVE-2025-7072 | CRITICAL | 9.3 | 0.5% | Jan 9, 2026 | The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route... |
| CVE-2025-66050 | CRITICAL | 9.8 | 0.3% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as ... |
| CVE-2025-64093 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname... |
| CVE-2025-13761 | CRITICAL | 9.6 | 0.6% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th... |
| CVE-2025-69194 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat... |
| CVE-2025-14741 | CRITICAL | 9.1 | 0.4% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi... |
| CVE-2025-70974 | CRITICAL | 10 | 0.7% | Jan 9, 2026 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i... |
| CVE-2025-14736 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i... |
| CVE-2025-68717 | CRITICAL | 9.4 | 0.5% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l... |
| CVE-2025-68715 | CRITICAL | 9.1 | 0.6% | Jan 8, 2026 | An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor... |
| CVE-2025-66916 | CRITICAL | 9.4 | 0.6% | Jan 8, 2026 | The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression... |
| CVE-2025-66913 | CRITICAL | 9.8 | 0.9% | Jan 8, 2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a... |
| CVE-2025-67325 | CRITICAL | 9.8 | 0.8% | Jan 8, 2026 | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated... |
| CVE-2025-61548 | CRITICAL | 9.8 | 0.5% | Jan 8, 2026 | SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo... |
| CVE-2025-61546 | CRITICAL | 9.1 | 0.5% | Jan 8, 2026 | There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W... |
| CVE-2025-61246 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param... |
| CVE-2025-59470 | CRITICAL | 9 | 1.5% | Jan 8, 2026 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal... |
| CVE-2025-59469 | CRITICAL | 9 | 0.6% | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to write files as root. |
| CVE-2025-59468 | CRITICAL | 9.1 | 1.1% | Jan 8, 2026 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ... |
| CVE-2025-56425 | CRITICAL | 9.1 | 0.6% | Jan 8, 2026 | An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto... |
| CVE-2025-55125 | CRITICAL | 9.8 | 0.8% | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio... |
| CVE-2025-69258 | CRITICAL | 9.8 | 3.2% | Jan 8, 2026 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta... |
| CVE-2025-62877 | CRITICAL | 9.8 | 0.5% | Jan 8, 2026 | Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now