2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41006 | CRITICAL | 9.3 | 0.3% | Jan 12, 2026 | Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’. |
| CVE-2025-69270 | CRITICAL | 9.8 | 0.3% | Jan 12, 2026 | Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux... |
| CVE-2025-69269 | CRITICAL | 9.8 | 0.8% | Jan 12, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX ... |
| CVE-2025-52694 | CRITICAL | 9.8 | 37.9% | Jan 12, 2026 | Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb... |
| CVE-2025-15503 | CRITICAL | 9.8 | 1.9% | Jan 10, 2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele... |
| CVE-2025-15502 | CRITICAL | 9.8 | 5.6% | Jan 10, 2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ... |
| CVE-2025-65091 | CRITICAL | 10 | 0.3% | Jan 10, 2026 | XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t... |
| CVE-2025-61686 | CRITICAL | 9.1 | 16.1% | Jan 10, 2026 | React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version... |
| CVE-2025-15501 | CRITICAL | 9.8 | 6.4% | Jan 9, 2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct... |
| CVE-2025-15500 | CRITICAL | 9.8 | 5.6% | Jan 9, 2026 | A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un... |
| CVE-2025-15499 | CRITICAL | 9.8 | 5.3% | Jan 9, 2026 | A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af... |
| CVE-2025-70161 | CRITICAL | 9.8 | 24.1% | Jan 9, 2026 | EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe... |
| CVE-2025-69542 | CRITICAL | 9.8 | 8.4% | Jan 9, 2026 | A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner... |
| CVE-2025-69426 | CRITICAL | 10 | 0.4% | Jan 9, 2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s... |
| CVE-2025-69425 | CRITICAL | 10 | 0.7% | Jan 9, 2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2... |
| CVE-2025-15496 | CRITICAL | 9.8 | 0.3% | Jan 9, 2026 | A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/... |
| CVE-2025-15493 | CRITICAL | 9.8 | 0.4% | Jan 9, 2026 | A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/... |
| CVE-2025-14598 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites.... |
| CVE-2025-7072 | CRITICAL | 9.3 | 0.5% | Jan 9, 2026 | The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route... |
| CVE-2025-66050 | CRITICAL | 9.8 | 0.3% | Jan 9, 2026 | Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as ... |
| CVE-2025-64093 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname... |
| CVE-2025-13761 | CRITICAL | 9.6 | 0.6% | Jan 9, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th... |
| CVE-2025-69194 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat... |
| CVE-2025-14741 | CRITICAL | 9.1 | 0.4% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi... |
| CVE-2025-70974 | CRITICAL | 10 | 0.7% | Jan 9, 2026 | Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now