2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-41006CRITICAL9.3Imaster's MEMS Events CRM contains an SQL injection vulnerability in ‘phone’ parameter in ‘/memsdemo/login.php’.
CVE-2025-69270CRITICAL9.8Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux...
CVE-2025-69269CRITICAL9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Broadcom DX ...
CVE-2025-52694CRITICAL9.8Successful exploitation of the SQL injection vulnerability could allow an unauthenticated remote attacker to execute arb...
CVE-2025-15503CRITICAL9.8A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted ele...
CVE-2025-15502CRITICAL9.8A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element ...
CVE-2025-65091CRITICAL10XWiki Full Calendar Macro displays objects from the wiki on the calendar. Prior to version 2.4.5, users with the right t...
CVE-2025-61686CRITICAL9.1React Router is a router for React. In @react-router/node versions 7.0.0 through 7.9.3, @remix-run/deno prior to version...
CVE-2025-15501CRITICAL9.8A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the funct...
CVE-2025-15500CRITICAL9.8A vulnerability was found in Sangfor Operation and Maintenance Management System up to 3.0.8. This issue affects some un...
CVE-2025-15499CRITICAL9.8A vulnerability has been found in Sangfor Operation and Maintenance Management System up to 3.0.8. This vulnerability af...
CVE-2025-70161CRITICAL9.8EDIMAX BR-6208AC V2_1.02 is vulnerable to Command Injection. This arises because the pppUserName field is directly passe...
CVE-2025-69542CRITICAL9.8A Command Injection Vulnerability has been discovered in the DHCP daemon service of D-Link DIR895LA1 v102b07. The vulner...
CVE-2025-69426CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating s...
CVE-2025-69425CRITICAL10The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2...
CVE-2025-15496CRITICAL9.8A vulnerability was determined in guchengwuyue yshopmall up to 1.9.1. Affected is the function getPage of the file /api/...
CVE-2025-15493CRITICAL9.8A flaw has been found in RainyGao DocSys up to 2.02.36. The impacted element is an unknown function of the file src/com/...
CVE-2025-14598CRITICAL9.8BeeS Software Solutions BET Portal contains an SQL injection vulnerability in the login functionality of affected sites....
CVE-2025-7072CRITICAL9.3The firmware in KAON CG3000TC and CG3000T routers contains hard-coded credentials in clear text (shared across all route...
CVE-2025-66050CRITICAL9.8Vivotek IP7137 camera with firmware version 0200a by default dos not require to provide any password when logging in as ...
CVE-2025-64093CRITICAL9.8Remote Code Execution vulnerability that allows unauthenticated attackers to inject arbitrary commands into the hostname...
CVE-2025-13761CRITICAL9.6GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 th...
CVE-2025-69194CRITICAL9.8A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validat...
CVE-2025-14741CRITICAL9.1The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to missing authorization to unauthorized data modifi...
CVE-2025-70974CRITICAL10Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key i...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now