2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-22957 | CRITICAL | 9.8 | 0.5% | Jan 31, 2025 | A SQL injection vulnerability exists in the front-end of the website in ZZCMS <= 2023, which can be exploited without an... |
| CVE-2025-23215 | CRITICAL | 9.3 | 0.3% | Jan 31, 2025 | PMD is an extensible multilanguage static code analyzer. The passphrase for the PMD and PMD Designer release signing key... |
| CVE-2025-0929 | CRITICAL | 9.8 | 0.8% | Jan 31, 2025 | SQL injection vulnerability in TeamCal Neo, version 3.8.2. This could allow an attacker to retrieve, update and delete a... |
| CVE-2025-0493 | CRITICAL | 9.8 | 1.0% | Jan 31, 2025 | The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limit... |
| CVE-2025-0881 | CRITICAL | 9.8 | 0.4% | Jan 30, 2025 | A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unkn... |
| CVE-2025-0880 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. This issue affects some unkn... |
| CVE-2025-0147 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | Type confusion in the Zoom Workplace App for Linux before 6.2.10 may allow an authorized user to conduct an escalation o... |
| CVE-2025-24503 | CRITICAL | 9.3 | 0.2% | Jan 30, 2025 | A malicious actor can fix the session of a PAM user by tricking the user to click on a specially crafted link to the PAM... |
| CVE-2025-0680 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attac... |
| CVE-2025-0874 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability, which was classified as critical, has been found in code-projects Simple Plugins Car Rental Management ... |
| CVE-2025-0498 | CRITICAL | 9.8 | 0.4% | Jan 30, 2025 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre... |
| CVE-2025-0497 | CRITICAL | 9.8 | 0.3% | Jan 30, 2025 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre... |
| CVE-2025-0477 | CRITICAL | 9.8 | 0.4% | Jan 30, 2025 | An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. ... |
| CVE-2025-0873 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability classified as critical was found in itsourcecode Tailoring Management System 1.0. Affected by this vulne... |
| CVE-2025-22219 | CRITICAL | 9 | 0.6% | Jan 30, 2025 | VMware Aria Operations for Logs contains a stored cross-site scripting vulnerability. A malicious actor with non-adminis... |
| CVE-2025-0872 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability classified as critical has been found in itsourcecode Tailoring Management System 1.0. Affected is an un... |
| CVE-2025-0848 | CRITICAL | 9.8 | 1.1% | Jan 30, 2025 | A vulnerability was found in Tenda A18 up to 15.13.07.09. It has been rated as critical. This issue affects the function... |
| CVE-2025-0847 | CRITICAL | 9.8 | 0.6% | Jan 30, 2025 | A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been declared as critical. This v... |
| CVE-2025-0846 | CRITICAL | 9.8 | 0.5% | Jan 30, 2025 | A vulnerability was found in 1000 Projects Employee Task Management System 1.0. It has been classified as critical. This... |
| CVE-2025-0843 | CRITICAL | 9.8 | 0.6% | Jan 29, 2025 | A vulnerability was found in needyamin Library Card System 1.0. It has been classified as critical. Affected is an unkno... |
| CVE-2025-0851 | CRITICAL | 9.8 | 23.1% | Jan 29, 2025 | A path traversal issue in ZipUtils.unzip and TarUtils.untar in Deep Java Library (DJL) on all platforms allows a bad act... |
| CVE-2025-0842 | CRITICAL | 9.8 | 0.6% | Jan 29, 2025 | A vulnerability was found in needyamin Library Card System 1.0 and classified as critical. This issue affects some unkno... |
| CVE-2025-20061 | CRITICAL | 9.8 | 1.2% | Jan 29, 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerabil... |
| CVE-2025-20014 | CRITICAL | 9.8 | 1.2% | Jan 29, 2025 | mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerab... |
| CVE-2025-0803 | CRITICAL | 9.8 | 0.6% | Jan 29, 2025 | A vulnerability, which was classified as critical, has been found in Codezips Gym Management System 1.0. Affected by thi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now