2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25349 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem pa... |
| CVE-2025-0332 | CRITICAL | 9.8 | 0.4% | Feb 12, 2025 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target... |
| CVE-2025-26361 | CRITICAL | 9.1 | 0.8% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26359 | CRITICAL | 9.8 | 0.9% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o... |
| CVE-2025-26347 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq... |
| CVE-2025-26345 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq... |
| CVE-2025-26344 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than... |
| CVE-2025-26342 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o... |
| CVE-2025-26341 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o... |
| CVE-2025-26339 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal... |
| CVE-2025-1100 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allow... |
| CVE-2025-1188 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by thi... |
| CVE-2025-1186 | CRITICAL | 9.8 | 0.6% | Feb 12, 2025 | A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects ... |
| CVE-2025-26520 | CRITICAL | 9.8 | 0.4% | Feb 12, 2025 | Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template paramete... |
| CVE-2025-1183 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulner... |
| CVE-2025-25530 | CRITICAL | 9.8 | 0.8% | Feb 11, 2025 | Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which... |
| CVE-2025-1044 | CRITICAL | 9.8 | 73.3% | Feb 11, 2025 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas... |
| CVE-2025-24434 | CRITICAL | 9.1 | 15.9% | Feb 11, 2025 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect A... |
| CVE-2025-21198 | CRITICAL | 9 | 0.9% | Feb 11, 2025 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability |
| CVE-2025-1126 | CRITICAL | 9.3 | 0.2% | Feb 11, 2025 | A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management ... |
| CVE-2025-24973 | CRITICAL | 9.3 | 0.2% | Feb 11, 2025 | Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1... |
| CVE-2025-26492 | CRITICAL | 9.1 | 0.4% | Feb 11, 2025 | In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources |
| CVE-2025-24956 | CRITICAL | 9.8 | 0.4% | Feb 11, 2025 | A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a len... |
| CVE-2025-26410 | CRITICAL | 9.8 | 0.7% | Feb 11, 2025 | The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password ca... |
| CVE-2025-0181 | CRITICAL | 9.8 | 0.6% | Feb 11, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now