2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1302 | CRITICAL | 9.8 | 10.7% | Feb 15, 2025 | Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input ... |
| CVE-2025-26508 | CRITICAL | 9.8 | 0.9% | Feb 14, 2025 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot... |
| CVE-2025-26507 | CRITICAL | 9.8 | 0.9% | Feb 14, 2025 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot... |
| CVE-2025-26506 | CRITICAL | 9.8 | 1.0% | Feb 14, 2025 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot... |
| CVE-2025-24607 | CRITICAL | 9.8 | 0.4% | Feb 14, 2025 | Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configu... |
| CVE-2025-0867 | CRITICAL | 9.9 | 0.6% | Feb 14, 2025 | The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that... |
| CVE-2025-1298 | CRITICAL | 9.8 | 0.4% | Feb 14, 2025 | Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover. |
| CVE-2025-22630 | CRITICAL | 9.9 | 1.2% | Feb 14, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widg... |
| CVE-2025-25067 | CRITICAL | 9.8 | 1.7% | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrar... |
| CVE-2025-24865 | CRITICAL | 9.8 | 6.8% | Feb 13, 2025 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an... |
| CVE-2025-24861 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | An attacker may inject commands via specially-crafted post requests. |
| CVE-2025-1283 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na... |
| CVE-2025-1127 | CRITICAL | 9.1 | 0.5% | Feb 13, 2025 | The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the co... |
| CVE-2025-25389 | CRITICAL | 9.8 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allow... |
| CVE-2025-25388 | CRITICAL | 9.8 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which all... |
| CVE-2025-0896 | CRITICAL | 9.8 | 2.4% | Feb 13, 2025 | Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. Thi... |
| CVE-2025-25286 | CRITICAL | 9.8 | 0.9% | Feb 13, 2025 | Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior t... |
| CVE-2025-1226 | CRITICAL | 9.8 | 0.8% | Feb 12, 2025 | A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown... |
| CVE-2025-0108 | CRITICAL | 9.1 | 98.3% | Feb 12, 2025 | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network acce... |
| CVE-2025-25343 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function. |
| CVE-2025-25746 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param... |
| CVE-2025-25744 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param... |
| CVE-2025-25742 | CRITICAL | 9.8 | 0.6% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPasswor... |
| CVE-2025-25182 | CRITICAL | 9.4 | 0.6% | Feb 12, 2025 | Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and p... |
| CVE-2025-25351 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now