2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14736 | CRITICAL | 9.8 | 0.7% | Jan 9, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and i... |
| CVE-2025-68717 | CRITICAL | 9.4 | 0.5% | Jan 8, 2026 | KAYSUS KS-WR3600 routers with firmware 1.0.5.9.1 allow authentication bypass during session validation. If any user is l... |
| CVE-2025-68715 | CRITICAL | 9.1 | 0.6% | Jan 8, 2026 | An issue was discovered in Panda Wireless PWRU0 devices with firmware 2.2.9 that exposes multiple HTTP endpoints (/gofor... |
| CVE-2025-66916 | CRITICAL | 9.4 | 0.6% | Jan 8, 2026 | The snailjob component in RuoYi-Vue-Plus versions 5.5.1 and earlier, interface /snail-job/workflow/check-node-expression... |
| CVE-2025-66913 | CRITICAL | 9.8 | 0.9% | Jan 8, 2026 | JimuReport thru version 2.1.3 is vulnerable to remote code execution when processing user-controlled H2 JDBC URLs. The a... |
| CVE-2025-67325 | CRITICAL | 9.8 | 0.8% | Jan 8, 2026 | Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated... |
| CVE-2025-61548 | CRITICAL | 9.8 | 0.5% | Jan 8, 2026 | SQL Injection is present on the hfInventoryDistFormID parameter in the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpo... |
| CVE-2025-61546 | CRITICAL | 9.1 | 0.5% | Jan 8, 2026 | There is an issue on the /PSP/appNET/Store/CartV12.aspx/GetUnitPrice endpoint in edu Business Solutions Print Shop Pro W... |
| CVE-2025-61246 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in master/review_action.php via the proId param... |
| CVE-2025-59470 | CRITICAL | 9 | 1.5% | Jan 8, 2026 | This vulnerability allows a Backup Operator to perform remote code execution (RCE) as the postgres user by sending a mal... |
| CVE-2025-59469 | CRITICAL | 9 | 0.6% | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to write files as root. |
| CVE-2025-59468 | CRITICAL | 9.1 | 1.1% | Jan 8, 2026 | This vulnerability allows a Backup Administrator to perform remote code execution (RCE) as the postgres user by sending ... |
| CVE-2025-56425 | CRITICAL | 9.1 | 0.6% | Jan 8, 2026 | An issue was discovered in the AppConnector component version 10.10.0.183 and earlier of enaio 10.10, in the AppConnecto... |
| CVE-2025-55125 | CRITICAL | 9.8 | 0.8% | Jan 8, 2026 | This vulnerability allows a Backup or Tape Operator to perform remote code execution (RCE) as root by creating a malicio... |
| CVE-2025-69258 | CRITICAL | 9.8 | 3.2% | Jan 8, 2026 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an atta... |
| CVE-2025-62877 | CRITICAL | 9.8 | 0.5% | Jan 8, 2026 | Projects using the SUSE Virtualization (Harvester) environment may expose the OS default ssh login password if they are... |
| CVE-2025-67928 | CRITICAL | 9.3 | 0.3% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in themesuite Automot... |
| CVE-2025-67924 | CRITICAL | 9.9 | 0.3% | Jan 8, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in zozothemes Corpkit corpkit allows Upload a Web Shell to... |
| CVE-2025-67911 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injecti... |
| CVE-2025-67910 | CRITICAL | 9.1 | 0.3% | Jan 8, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in contentstudio Contentstudio contentstudio allows Upload... |
| CVE-2025-23993 | CRITICAL | 9.3 | 0.4% | Jan 8, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RiceTheme Felan Fr... |
| CVE-2025-23504 | CRITICAL | 9.8 | 0.4% | Jan 8, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in RiceTheme Felan Framework felan-framework allo... |
| CVE-2025-15346 | CRITICAL | 9.3 | 0.3% | Jan 8, 2026 | A vulnerability in the handling of verify_mode = CERT_REQUIRED in the wolfssl Python package (wolfssl-py) causes client ... |
| CVE-2025-69264 | CRITICAL | 9.8 | 1.0% | Jan 7, 2026 | pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during ... |
| CVE-2025-68705 | CRITICAL | 9.8 | 6.6% | Jan 7, 2026 | RustFS is a distributed object storage system built in Rust. In versions 1.0.0-alpha.13 to 1.0.0-alpha.78, RustFS contai... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now