2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-36747 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | ShineLan-X contains a set of credentials for an FTP server was found within the firmware, allowing testers to establish ... |
| CVE-2025-14620 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unkno... |
| CVE-2025-14619 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-14590 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown functio... |
| CVE-2025-14588 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown co... |
| CVE-2025-14587 | CRITICAL | 9.8 | 0.3% | Dec 13, 2025 | A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of th... |
| CVE-2025-14586 | CRITICAL | 9.8 | 2.5% | Dec 13, 2025 | A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224. Affected by this issue is the function snprint... |
| CVE-2025-14440 | CRITICAL | 9.8 | 0.7% | Dec 13, 2025 | The JAY Login & Register plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2... |
| CVE-2025-11693 | CRITICAL | 9.8 | 2.0% | Dec 13, 2025 | The Export WP Page to Static HTML & PDF plugin for WordPress is vulnerable to Sensitive Information Exposure in all vers... |
| CVE-2025-10738 | CRITICAL | 9.8 | 0.4% | Dec 13, 2025 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to SQL Injection via the ‘analytic_id’ paramet... |
| CVE-2025-14585 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functi... |
| CVE-2025-14584 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /a... |
| CVE-2025-14583 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A flaw has been found in campcodes Online Student Enrollment System 1.0. This impacts an unknown function of the file /a... |
| CVE-2025-14611 | CRITICAL | 9.8 | 50.9% | Dec 12, 2025 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of th... |
| CVE-2025-14578 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown functio... |
| CVE-2025-14571 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u... |
| CVE-2025-14570 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-66430 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Plesk 18.0 has Incorrect Access Control. |
| CVE-2025-65854 | CRITICAL | 9.8 | 0.5% | Dec 12, 2025 | Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and... |
| CVE-2025-14566 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The ... |
| CVE-2025-14565 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affec... |
| CVE-2025-54947 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | In Apache StreamPark versions 2.0.0 through 2.1.7, a security vulnerability involving a hard-coded encryption key exists... |
| CVE-2025-58130 | CRITICAL | 9.1 | 0.4% | Dec 12, 2025 | Insufficiently Protected Credentials vulnerability in Apache Fineract. This issue affects Apache Fineract: through 1.11... |
| CVE-2025-67728 | CRITICAL | 9.8 | 0.6% | Dec 12, 2025 | Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unau... |
| CVE-2025-67727 | CRITICAL | 9.8 | 0.4% | Dec 12, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that runs Node.js. In versions prior t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now