2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-0532 | CRITICAL | 9.8 | 0.6% | Jan 17, 2025 | A vulnerability was found in Codezips Gym Management System 1.0. It has been classified as critical. Affected is an unkn... |
| CVE-2025-0527 | CRITICAL | 9.8 | 0.7% | Jan 17, 2025 | A vulnerability classified as critical was found in code-projects Admission Management System 1.0. Affected by this vuln... |
| CVE-2025-23922 | CRITICAL | 10 | 1.0% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Harsh iSpring Embedder embed-ispring allows Upload a Web Shell to a W... |
| CVE-2025-23797 | CRITICAL | 9.8 | 0.3% | Jan 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mike Selander WP Options Editor wp-options-editor allows Privilege Es... |
| CVE-2025-0471 | CRITICAL | 9.8 | 0.6% | Jan 16, 2025 | Unrestricted file upload vulnerability in the PMB platform, affecting versions 4.0.10 and above. This vulnerability coul... |
| CVE-2025-22916 | CRITICAL | 9.8 | 0.7% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the pppUserName parameter in the formPPPoESetup function. |
| CVE-2025-22913 | CRITICAL | 9.8 | 0.8% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the rootAPmac parameter in the formStaDrvSetup function. |
| CVE-2025-22912 | CRITICAL | 9.8 | 2.3% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept. |
| CVE-2025-22907 | CRITICAL | 9.8 | 0.9% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the selSSID parameter in the formWlSiteSurvey function. |
| CVE-2025-22906 | CRITICAL | 9.8 | 2.7% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN... |
| CVE-2025-22905 | CRITICAL | 9.8 | 5.6% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp. |
| CVE-2025-22904 | CRITICAL | 9.8 | 0.7% | Jan 16, 2025 | RE11S v1.11 was discovered to contain a stack overflow via the pptpUserName parameter in the setWAN function. |
| CVE-2025-0456 | CRITICAL | 9.8 | 0.8% | Jan 16, 2025 | The airPASS from NetVision Information has a Missing Authentication vulnerability, allowing unauthenticated remote attac... |
| CVE-2025-0455 | CRITICAL | 9.8 | 0.5% | Jan 16, 2025 | The airPASS from NetVision Information has a SQL Injection vulnerability, allowing unauthenticated remote attackers to i... |
| CVE-2025-0491 | CRITICAL | 9.8 | 0.6% | Jan 15, 2025 | A vulnerability, which was classified as critical, was found in Fanli2012 native-php-cms 1.0. Affected is an unknown fun... |
| CVE-2025-0487 | CRITICAL | 9.8 | 0.5% | Jan 15, 2025 | A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been rated as critical. Affected by this issue is some... |
| CVE-2025-0486 | CRITICAL | 9.8 | 0.5% | Jan 15, 2025 | A vulnerability was found in Fanli2012 native-php-cms 1.0. It has been declared as critical. Affected by this vulnerabil... |
| CVE-2025-22146 | CRITICAL | 9.1 | 0.6% | Jan 15, 2025 | Sentry is a developer-first error tracking and performance monitoring tool. A critical vulnerability was discovered in t... |
| CVE-2025-0502 | CRITICAL | 9.1 | 0.4% | Jan 15, 2025 | Transmission of Private Resources into a New Sphere ('Resource Leak') vulnerability in CrafterCMS Engine on Linux, MacOS... |
| CVE-2025-22968 | CRITICAL | 9.8 | 2.5% | Jan 15, 2025 | An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account witho... |
| CVE-2025-22785 | CRITICAL | 9.3 | 2.8% | Jan 15, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course B... |
| CVE-2025-22782 | CRITICAL | 9.9 | 0.5% | Jan 15, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Web Ready Now WR Price List Manager For Woocommerce wr-... |
| CVE-2025-23061 | CRITICAL | 9.8 | 7.0% | Jan 15, 2025 | Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NO... |
| CVE-2025-21311 | CRITICAL | 9.8 | 2.3% | Jan 14, 2025 | Windows NTLM V1 Elevation of Privilege Vulnerability |
| CVE-2025-21307 | CRITICAL | 9.8 | 1.8% | Jan 14, 2025 | Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now