2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-15493CRITICAL9.8A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/...
CVE-2025-14598CRITICAL9.8BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites....
CVE-2025-7072CRITICAL9.3The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route...
CVE-2025-66050CRITICAL9.8Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as ...
CVE-2025-64093CRITICAL9.8Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname...
CVE-2025-13761CRITICAL9.6GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th...
CVE-2025-69194CRITICAL9.8A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat...
CVE-2025-14741CRITICAL9.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi...
CVE-2025-70974CRITICAL10Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i...
CVE-2025-14736CRITICAL9.8The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i...
CVE-2025-68717CRITICAL9.4KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l...
CVE-2025-68715CRITICAL9.1An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor...
CVE-2025-66916CRITICAL9.4The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression...
CVE-2025-66913CRITICAL9.8JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a...
CVE-2025-67325CRITICAL9.8Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated...
CVE-2025-61548CRITICAL9.8SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo...
CVE-2025-61546CRITICAL9.1There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W...
CVE-2025-61246CRITICAL9.8indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param...
CVE-2025-59470CRITICAL9This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal...
CVE-2025-59469CRITICAL9This vulnerability allows a Backup or Tape Operator to write files as root.
CVE-2025-59468CRITICAL9.1This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ...
CVE-2025-56425CRITICAL9.1An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto...
CVE-2025-55125CRITICAL9.8This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio...
CVE-2025-69258CRITICAL9.8A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta...
CVE-2025-62877CRITICAL9.8Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password  if they are...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now