2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-15077CRITICAL9.8A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unk...
CVE-2025-15076HIGH7.3A weakness has been identified in Tenda CH22 1.0.0.1. Impacted is an unknown function of the file /public/. Executing a ...
CVE-2025-15075CRITICAL9.8A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown proce...
CVE-2025-15074CRITICAL9.8A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unkno...
CVE-2025-68922HIGH7.4OpenOps before 0.6.11 allows remote code execution in the Terraform block.
CVE-2025-15073CRITICAL9.8A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of ...
CVE-2025-68920HIGH8.9C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 244644d allows a remote Kermit system to overwrite f...
CVE-2025-8769CRITICAL9.8Telenium Online Web Application is vulnerable due to a Perl script that is called to load the login page. Due to improp...
CVE-2025-68919MEDIUM5.6Fujitsu / Fsas Technologies ETERNUS SF ACM/SC/Express (DX / AF Management Software) before 16.8-16.9.1 PA 2025-12, when ...
CVE-2025-68917MEDIUM6.4ONLYOFFICE Docs before 9.2.1 allows XSS in the textarea of the comment editing form. This is related to DocumentServer.
CVE-2025-68916HIGH7.2Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/certsupload.cgi /../ directory traversal for file upload wi...
CVE-2025-68915MEDIUM4.8Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/loginbanner_w.cgi XSS via a crafted banner.
CVE-2025-68914MEDIUM5.3Riello UPS NetMan 208 Application before 1.12 allows cgi-bin/login.cgi username SQL Injection. For example, an attacker ...
CVE-2025-3232HIGH8.7A remote unauthenticated attacker may be able to bypass authentication by utilizing a specific API route to execute arb...
CVE-2025-36154MEDIUM6.2IBM Concert 1.0.0 through 2.1.0 stores sensitive information in cleartext during recursive docker builds which could be ...
CVE-2025-2515HIGH7.2A vulnerability was found in BlueChi, a multi-node systemd service controller used in RHIVOS. This flaw allows a user wi...
CVE-2025-68750In the Linux kernel, the following vulnerability has been resolved: usb: potential integer overflow in usbg_make_tpg() ...
CVE-2025-43876HIGH8.7Under certain circumstances a successful exploitation could result in access to the device.
CVE-2025-43875HIGH8.7Under certain circumstances a successful exploitation could result in access to the device.
CVE-2025-60935MEDIUM6.1An open redirect vulnerability in the login endpoint of Blitz Panel v1.17.0 allows attackers to redirect users to malici...
CVE-2025-2155HIGH8.8Unrestricted Upload of File with Dangerous Type vulnerability in Echo Call Center Services Trade and Industry Inc. Spect...
CVE-2025-2154MEDIUM5.4Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Echo Call C...
CVE-2025-5448Rejected reason: This CVE id was assigned but later discarded.
CVE-2025-68749MEDIUM4.7In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Fix race condition when unbinding BOs ...
CVE-2025-68748HIGH7.8In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix UAF race between device unplug and...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now