2025 CVE Vulnerabilities

45,153 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15194CRITICAL9.8A vulnerability was found in D-Link DIR-600 up to 2.15WWb02. Affected by this vulnerability is an unknown functionality ...
CVE-2025-68929CRITICAL9Frappe is a full-stack web application framework. Prior to versions 14.99.6 and 15.88.1, an authenticated user with spec...
CVE-2025-68928MEDIUM5.4Frappe CRM is an open-source customer relationship management tool. Prior to version 1.56.2, authenticated users could s...
CVE-2025-65570CRITICAL9.8A type confusion in jsish 2.0 allows incorrect control flow during execution of the OP_NEXT opcode. When an “instanceof”...
CVE-2025-65442MEDIUM6.1DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrar...
CVE-2025-60458MEDIUM6.5UxPlay 1.72 contains a double free vulnerability in its RTSP request handling. A specially crafted RTSP TEARDOWN request...
CVE-2025-57462MEDIUM6.1Stored cross-site scripting (xss) in machsol machpanel 8.0.32 allows attackers to execute arbitrary web scripts or HTML ...
CVE-2025-15193HIGH8.8A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/f...
CVE-2025-15192HIGH8.8A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415...
CVE-2025-57460CRITICAL9.8File upload vulnerability in machsol machpanel 8.0.32 allows attacker to gain a webshell.
CVE-2025-15191HIGH8.8A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the f...
CVE-2025-15190HIGH8.8A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42261C of the file /bo...
CVE-2025-15189HIGH8.8A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /...
CVE-2025-15188MEDIUM4.8A vulnerability was determined in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe...
CVE-2025-15187MEDIUM6.5A vulnerability was found in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of t...
CVE-2025-15186CRITICAL9.8A vulnerability has been found in code-projects Refugee Food Management System 1.0. Affected by this issue is some unkno...
CVE-2025-15185CRITICAL9.8A flaw has been found in code-projects Refugee Food Management System 1.0. Affected by this vulnerability is an unknown ...
CVE-2025-15184CRITICAL9.8A vulnerability was detected in code-projects Refugee Food Management System 1.0. Affected is an unknown function of the...
CVE-2025-15183CRITICAL9.8A security vulnerability has been detected in code-projects Refugee Food Management System 1.0. This impacts an unknown ...
CVE-2025-15182CRITICAL9.8A weakness has been identified in code-projects Refugee Food Management System 1.0. This affects an unknown function of ...
CVE-2025-15181CRITICAL9.8A security flaw has been discovered in code-projects Refugee Food Management System 1.0. The impacted element is an unkn...
CVE-2025-15180HIGH7.3A vulnerability was identified in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/...
CVE-2025-15228CRITICAL9.8BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Upload vulnerability, allowing unauthenticated remot...
CVE-2025-15227HIGH8.7BPMFlowWebkit developed by WELLTEND TECHNOLOGY has a Arbitrary File Read vulnerability, allowing unauthenticated remote ...
CVE-2025-15179HIGH7.3A vulnerability was determined in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/qossetting. ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now