2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1283 | CRITICAL | 9.8 | 0.5% | Feb 13, 2025 | The Dingtian DT-R0 Series is vulnerable to an exploit that allows attackers to bypass login requirements by directly na... |
| CVE-2025-1127 | CRITICAL | 9.1 | 0.5% | Feb 13, 2025 | The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the co... |
| CVE-2025-25389 | CRITICAL | 9.8 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/forgot-password.php in Phpgurukul Land Record System v1.0, which allow... |
| CVE-2025-25388 | CRITICAL | 9.8 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/edit-propertytype.php in PHPGurukul Land Record System v1.0, which all... |
| CVE-2025-0896 | CRITICAL | 9.8 | 2.4% | Feb 13, 2025 | Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. Thi... |
| CVE-2025-25286 | CRITICAL | 9.8 | 0.9% | Feb 13, 2025 | Crayfish is a collection of Islandora 8 microservices, one of which, Homarus, provides FFmpeg as a microservice. Prior t... |
| CVE-2025-1226 | CRITICAL | 9.8 | 0.8% | Feb 12, 2025 | A vulnerability was found in ywoa up to 2024.07.03. It has been declared as critical. This vulnerability affects unknown... |
| CVE-2025-0108 | CRITICAL | 9.1 | 98.5% | Feb 12, 2025 | An authentication bypass in the Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network acce... |
| CVE-2025-25343 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | Tenda AC6 V15.03.05.16 firmware has a buffer overflow vulnerability in the formexeCommand function. |
| CVE-2025-25746 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param... |
| CVE-2025-25744 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the Password param... |
| CVE-2025-25742 | CRITICAL | 9.8 | 0.6% | Feb 12, 2025 | D-Link DIR-853 A1 FW1.20B07 was discovered to contain a stack-based buffer overflow vulnerability via the AccountPasswor... |
| CVE-2025-25182 | CRITICAL | 9.4 | 0.6% | Feb 12, 2025 | Stroom is a data processing, storage and analysis platform. A vulnerability exists starting in version 7.2-beta.53 and p... |
| CVE-2025-25351 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the dateexpense... |
| CVE-2025-25349 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | PHPGurukul Daily Expense Tracker System v1.1 is vulnerable to SQL Injection in /dets/add-expense.php via the costitem pa... |
| CVE-2025-0332 | CRITICAL | 9.8 | 0.4% | Feb 12, 2025 | In Progress® Telerik® UI for WinForms, versions prior to 2025 Q1 (2025.1.211), using the improper limitation of a target... |
| CVE-2025-26361 | CRITICAL | 9.1 | 0.8% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26359 | CRITICAL | 9.8 | 0.9% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o... |
| CVE-2025-26347 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq... |
| CVE-2025-26345 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/menu/routes.lua in Q-Free MaxTime less than or eq... |
| CVE-2025-26344 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/guest-mode/routes.lua in Q-Free MaxTime less than... |
| CVE-2025-26342 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o... |
| CVE-2025-26341 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/accounts/routes.lua in Q-Free MaxTime less than o... |
| CVE-2025-26339 | CRITICAL | 9.8 | 1.0% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxtime/handleRoute.lua in Q-Free MaxTime less than or equal... |
| CVE-2025-1100 | CRITICAL | 9.8 | 0.7% | Feb 12, 2025 | A CWE-259 "Use of Hard-coded Password" for the root account in Q-Free MaxTime less than or equal to version 2.11.0 allow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now