2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41734 | CRITICAL | 9.8 | 0.5% | Nov 18, 2025 | An unauthenticated remote attacker can execute arbitrary php files and gain full access of the affected devices. |
| CVE-2025-41733 | CRITICAL | 9.8 | 0.6% | Nov 18, 2025 | The commissioning wizard on the affected devices does not validate if the device is already initialized. An unauthentica... |
| CVE-2025-41347 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | Unlimited upload vulnerability for dangerous file types in WinPlus v24.11.27 from Informática del Este. This vulnerabili... |
| CVE-2025-41346 | CRITICAL | 9.8 | 0.3% | Nov 18, 2025 | Faulty authorization control in software WinPlus v24.11.27 by Informática del Este that allows another user to be impers... |
| CVE-2025-40549 | CRITICAL | 9.1 | 1.0% | Nov 18, 2025 | A Path Restriction Bypass vulnerability exists in Serv-U that when abused, could give a malicious actor with access to a... |
| CVE-2025-40548 | CRITICAL | 9.1 | 0.6% | Nov 18, 2025 | A missing validation process exists in Serv U when abused, could give a malicious actor with access to admin privileges ... |
| CVE-2025-40547 | CRITICAL | 9.1 | 0.8% | Nov 18, 2025 | A logic error vulnerability exists in Serv-U which when abused could give a malicious actor with access to admin privile... |
| CVE-2025-13323 | CRITICAL | 9.8 | 0.4% | Nov 18, 2025 | A security flaw has been discovered in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function o... |
| CVE-2025-13305 | CRITICAL | 9.8 | 3.2% | Nov 17, 2025 | A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects... |
| CVE-2025-13303 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown fu... |
| CVE-2025-13302 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file ... |
| CVE-2025-13301 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerab... |
| CVE-2025-13300 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unkno... |
| CVE-2025-13299 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown funct... |
| CVE-2025-13298 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknow... |
| CVE-2025-55058 | CRITICAL | 9.8 | 0.2% | Nov 17, 2025 | CWE-20 Improper Input Validation |
| CVE-2025-55055 | CRITICAL | 9.8 | 0.7% | Nov 17, 2025 | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2025-13297 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impa... |
| CVE-2025-13291 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufac... |
| CVE-2025-63747 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immedia... |
| CVE-2025-13285 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of ... |
| CVE-2025-13280 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of ... |
| CVE-2025-13277 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of th... |
| CVE-2025-13272 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function o... |
| CVE-2025-13271 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was determined in Campcodes School Fees Payment Management System 1.0. This impacts an unknown function ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now