2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26623 | CRITICAL | 9.8 | 0.8% | Feb 18, 2025 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2025-22654 | CRITICAL | 10 | 0.9% | Feb 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious F... |
| CVE-2025-24895 | CRITICAL | 9.1 | 0.6% | Feb 18, 2025 | CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is ba... |
| CVE-2025-24894 | CRITICAL | 9.1 | 0.6% | Feb 18, 2025 | SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is base... |
| CVE-2025-1023 | CRITICAL | 9.8 | 2.2% | Feb 18, 2025 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit... |
| CVE-2025-25222 | CRITICAL | 9.8 | 0.4% | Feb 18, 2025 | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v... |
| CVE-2025-25221 | CRITICAL | 9.8 | 0.4% | Feb 18, 2025 | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v... |
| CVE-2025-1380 | CRITICAL | 9.8 | 0.5% | Feb 17, 2025 | A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is so... |
| CVE-2025-1379 | CRITICAL | 9.8 | 0.5% | Feb 17, 2025 | A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. A... |
| CVE-2025-1387 | CRITICAL | 9.8 | 0.5% | Feb 17, 2025 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers t... |
| CVE-2025-22290 | CRITICAL | 9.3 | 0.3% | Feb 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ... |
| CVE-2025-22289 | CRITICAL | 9.8 | 0.4% | Feb 16, 2025 | Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-uni... |
| CVE-2025-1355 | CRITICAL | 9.8 | 0.8% | Feb 16, 2025 | A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2025-26793 | CRITICAL | 9.3 | 2.3% | Feb 15, 2025 | The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with defaul... |
| CVE-2025-1302 | CRITICAL | 9.8 | 10.7% | Feb 15, 2025 | Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input ... |
| CVE-2025-26508 | CRITICAL | 9.8 | 0.9% | Feb 14, 2025 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot... |
| CVE-2025-26507 | CRITICAL | 9.8 | 0.9% | Feb 14, 2025 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot... |
| CVE-2025-26506 | CRITICAL | 9.8 | 1.0% | Feb 14, 2025 | Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remot... |
| CVE-2025-24607 | CRITICAL | 9.8 | 0.4% | Feb 14, 2025 | Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configu... |
| CVE-2025-0867 | CRITICAL | 9.9 | 0.6% | Feb 14, 2025 | The standard user uses the run as function to start the MEAC applications with administrative privileges. To ensure that... |
| CVE-2025-1298 | CRITICAL | 9.8 | 0.4% | Feb 14, 2025 | Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover. |
| CVE-2025-22630 | CRITICAL | 9.9 | 1.2% | Feb 14, 2025 | Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Marketing Fire Widg... |
| CVE-2025-25067 | CRITICAL | 9.8 | 1.7% | Feb 13, 2025 | mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrar... |
| CVE-2025-24865 | CRITICAL | 9.8 | 6.8% | Feb 13, 2025 | The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an... |
| CVE-2025-24861 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | An attacker may inject commands via specially-crafted post requests. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now