2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1188 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by thi... |
| CVE-2025-1186 | CRITICAL | 9.8 | 0.6% | Feb 12, 2025 | A vulnerability was found in dayrui XunRuiCMS up to 4.6.4. It has been declared as critical. This vulnerability affects ... |
| CVE-2025-26520 | CRITICAL | 9.8 | 0.4% | Feb 12, 2025 | Cacti through 1.2.29 allows SQL injection in the template function in host_templates.php via the graph_template paramete... |
| CVE-2025-1183 | CRITICAL | 9.8 | 0.5% | Feb 12, 2025 | A vulnerability has been found in CodeZips Gym Management System 1.0 and classified as critical. Affected by this vulner... |
| CVE-2025-25530 | CRITICAL | 9.8 | 0.8% | Feb 11, 2025 | Buffer overflow vulnerability in Digital China DCBI-Netlog-LAB Gateway 1.0 due to the lack of length verification, which... |
| CVE-2025-1044 | CRITICAL | 9.8 | 73.3% | Feb 11, 2025 | Logsign Unified SecOps Platform Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypas... |
| CVE-2025-24434 | CRITICAL | 9.1 | 15.9% | Feb 11, 2025 | Adobe Commerce versions 2.4.8-beta1, 2.4.7-p3, 2.4.6-p8, 2.4.5-p10, 2.4.4-p11 and earlier are affected by an Incorrect A... |
| CVE-2025-21198 | CRITICAL | 9 | 0.9% | Feb 11, 2025 | Microsoft High Performance Compute (HPC) Pack Remote Code Execution Vulnerability |
| CVE-2025-1126 | CRITICAL | 9.3 | 0.2% | Feb 11, 2025 | A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management ... |
| CVE-2025-24973 | CRITICAL | 9.3 | 0.2% | Feb 11, 2025 | Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1... |
| CVE-2025-26492 | CRITICAL | 9.1 | 0.4% | Feb 11, 2025 | In JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resources |
| CVE-2025-24956 | CRITICAL | 9.8 | 0.4% | Feb 11, 2025 | A vulnerability has been identified in OpenV2G (All versions < V0.9.6). The OpenV2G EXI parsing feature is missing a len... |
| CVE-2025-26410 | CRITICAL | 9.8 | 0.7% | Feb 11, 2025 | The firmware of all Wattsense Bridge devices contain the same hard-coded user and root credentials. The user password ca... |
| CVE-2025-0181 | CRITICAL | 9.8 | 0.6% | Feb 11, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to,... |
| CVE-2025-0180 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | The WP Foodbakery plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 4.7. ... |
| CVE-2025-1177 | CRITICAL | 9.8 | 0.7% | Feb 11, 2025 | A vulnerability was found in dayrui XunRuiCMS 4.6.3. It has been classified as critical. Affected is the function import... |
| CVE-2025-1144 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | School Affairs System from Quanxun has an Exposure of Sensitive Information, allowing unauthenticated attackers to view ... |
| CVE-2025-1168 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | A vulnerability was found in SourceCodester Contact Manager with Export to VCF 1.0. It has been declared as critical. Th... |
| CVE-2025-1167 | CRITICAL | 9.8 | 0.5% | Feb 11, 2025 | A vulnerability was found in Mayuri K Employee Management System up to 192.168.70.3 and classified as critical. Affected... |
| CVE-2025-1160 | CRITICAL | 9.8 | 0.8% | Feb 10, 2025 | A vulnerability was found in SourceCodester Employee Management System 1.0. It has been rated as critical. Affected by t... |
| CVE-2025-24016 | CRITICAL | 9.9 | 92.6% | Feb 10, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Starting in version 4.4.0 ... |
| CVE-2025-24032 | CRITICAL | 9.2 | 0.7% | Feb 10, 2025 | PAM-PKCS#11 is a Linux-PAM login module that allows a X.509 certificate based user login. Prior to version 0.6.13, if ce... |
| CVE-2025-0316 | CRITICAL | 9.8 | 0.7% | Feb 8, 2025 | The WP Directorybox Manager plugin for WordPress is vulnerable to authentication bypass in versions up to, and including... |
| CVE-2025-24028 | CRITICAL | 9.6 | 0.5% | Feb 7, 2025 | Joplin is a free, open source note taking and to-do application, which can handle a large number of notes organised into... |
| CVE-2025-1113 | CRITICAL | 9.8 | 0.5% | Feb 7, 2025 | A vulnerability was found in taisan tarzan-cms up to 1.0.0. It has been rated as critical. This issue affects the functi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now