2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27222 | HIGH | 8.6 | 1.9% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/getCobrandingData endpoint to retrieve files. However, t... |
| CVE-2025-12299 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown... |
| CVE-2025-12298 | MEDIUM | 6.1 | 0.4% | Oct 27, 2025 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. This affects an unknown part of the fil... |
| CVE-2025-12297 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A vulnerability was detected in atjiu pybbs up to 6.0.0. This affects an unknown function of the file UserApiController.... |
| CVE-2025-12296 | CRITICAL | 9.8 | 7.0% | Oct 27, 2025 | A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 ... |
| CVE-2025-12295 | HIGH | 8.1 | 0.4% | Oct 27, 2025 | A weakness has been identified in D-Link DAP-2695 2.00RC13. The affected element is the function sub_40C6B8 of the compo... |
| CVE-2025-61247 | HIGH | 8.2 | 0.2% | Oct 27, 2025 | indieka900 online-shopping-system-php 1.0 is vulnerable to SQL Injection in the password parameter of login.php. |
| CVE-2025-60791 | MEDIUM | 6.2 | 0.1% | Oct 27, 2025 | Easywork Enterprise 2.1.3.354 is vulnerable to Cleartext Storage of Sensitive Information in Memory. The application lea... |
| CVE-2025-60425 | HIGH | 8.6 | 0.9% | Oct 27, 2025 | Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authenticati... |
| CVE-2025-60424 | HIGH | 7.6 | 0.7% | Oct 27, 2025 | A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to byp... |
| CVE-2025-34133 | HIGH | 7 | 0.2% | Oct 27, 2025 | Wimi Teamwork versions prior to 7.38.17 contains a cross-site request forgery (CSRF) vulnerability in its API. The API a... |
| CVE-2025-12294 | CRITICAL | 9.8 | 0.3% | Oct 27, 2025 | A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /d... |
| CVE-2025-12293 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the f... |
| CVE-2025-12292 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file... |
| CVE-2025-12291 | MEDIUM | 4.7 | 0.3% | Oct 27, 2025 | A vulnerability was found in ashymuzuro Full-Ecommece-Website and Muzuro Ecommerce System up to 1.1.0. This affects an u... |
| CVE-2025-10023 | MEDIUM | 4.8 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Centreon In... |
| CVE-2025-61482 | HIGH | 7.2 | 0.1% | Oct 27, 2025 | Improper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local a... |
| CVE-2025-52268 | HIGH | 7.5 | 0.3% | Oct 27, 2025 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a hardcoded AES key which allows attackers to for... |
| CVE-2025-52264 | HIGH | 8 | 0.3% | Oct 27, 2025 | StarCharge Artemis AC Charger 7-22 kW v1.0.4 was discovered to contain a stack overflow via the cgiMain function at down... |
| CVE-2025-36121 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | IBM OpenPages 9.1 and 9.0 is vulnerable to HTML injection. A remotely authenticated attacker could inject malicious HTML... |
| CVE-2025-34292 | CRITICAL | 9.4 | 0.5% | Oct 27, 2025 | Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of unt... |
| CVE-2025-26862 | NONE | 0 | 0.3% | Oct 27, 2025 | Unexpected authentication form rendering in HTML Form Adapter using only non-default redirectless mode in PingFederate a... |
| CVE-2025-12351 | MEDIUM | 6.8 | 0.2% | Oct 27, 2025 | Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker cou... |
| CVE-2025-12290 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A vulnerability has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall Syste... |
| CVE-2025-12289 | MEDIUM | 4.3 | 0.3% | Oct 27, 2025 | A flaw has been found in Sui Shang Information Technology Suishang Enterprise-Level B2B2C Multi-User Mall System 1.0. Af... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now