2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26523 | HIGH | 7.4 | 0.4% | Feb 14, 2025 | This vulnerability exists in RupeeWeb trading platform due to insufficient authorization controls on certain API endpoin... |
| CVE-2025-26522 | HIGH | 7.5 | 0.4% | Feb 14, 2025 | This vulnerability exists in RupeeWeb trading platform due to improper implementation of OTP validation mechanism in cer... |
| CVE-2025-26788 | HIGH | 8.4 | 0.4% | Feb 14, 2025 | StrongKey FIDO Server before 4.15.1 treats a non-discoverable (namedcredential) flow as a discoverable transaction. |
| CVE-2025-26519 | HIGH | 7 | 0.3% | Feb 14, 2025 | musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write vulnerability when an attacker can trigger iconv ... |
| CVE-2025-22962 | HIGH | 7.2 | 0.9% | Feb 13, 2025 | A critical remote code execution (RCE) vulnerability exists in the web-based management interface of GatesAir Maxiva UAX... |
| CVE-2025-22961 | HIGH | 8 | 0.4% | Feb 13, 2025 | A critical information disclosure vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VA... |
| CVE-2025-22960 | HIGH | 8 | 0.4% | Feb 13, 2025 | A session hijacking vulnerability exists in the web-based management interface of GatesAir Maxiva UAXT, VAXT transmitter... |
| CVE-2025-26473 | HIGH | 7.5 | 0.4% | Feb 13, 2025 | The Mojave Inverter uses the GET method for sensitive information. |
| CVE-2025-25281 | HIGH | 7.5 | 0.4% | Feb 13, 2025 | An attacker may modify the URL to discover sensitive information about the target network. |
| CVE-2025-24836 | HIGH | 7.1 | 0.2% | Feb 13, 2025 | With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted... |
| CVE-2025-22896 | HIGH | 7.5 | 3.4% | Feb 13, 2025 | mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information. |
| CVE-2025-24888 | HIGH | 8.1 | 0.9% | Feb 13, 2025 | The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on ... |
| CVE-2025-25387 | HIGH | 7.2 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/manage-propertytype.php in PHPGurukul Land Record System v1.0, which a... |
| CVE-2025-26511 | HIGH | 8.8 | 0.5% | Feb 13, 2025 | Systems running the Instaclustr fork of Stratio's Cassandra-Lucene-Index plugin versions 4.0-rc1-1.0.0 through 4.0.16-... |
| CVE-2025-25901 | HIGH | 7.5 | 0.5% | Feb 13, 2025 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11, triggered by the dnsserver1 and dnsserver2 par... |
| CVE-2025-25898 | HIGH | 7.5 | 0.5% | Feb 13, 2025 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the pskSecret parameter at /userRpm/WlanSec... |
| CVE-2025-25897 | HIGH | 7.5 | 0.5% | Feb 13, 2025 | A buffer overflow vulnerability was discovered in TP-Link TL-WR841ND V11 via the 'ip' parameter at /userRpm/WanStaticIpV... |
| CVE-2025-25357 | HIGH | 7.2 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/contactus.php in PHPGurukul Land Record System v1.0, which allows remo... |
| CVE-2025-25356 | HIGH | 7.2 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, whi... |
| CVE-2025-25355 | HIGH | 7.2 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/bwdates-reports-details.php in PHPGurukul Land Record System v1.0, whi... |
| CVE-2025-25354 | HIGH | 7.2 | 0.7% | Feb 13, 2025 | A SQL Injection was found in /admin/admin-profile.php in PHPGurukul Land Record System v1.0, which allows remote attacke... |
| CVE-2025-25352 | HIGH | 7.2 | 0.7% | Feb 13, 2025 | A SQL Injection vulnerability was found in /admin/aboutus.php in PHPGurukul Land Record System v1.0, which allows remote... |
| CVE-2025-24904 | HIGH | 8.5 | 0.2% | Feb 13, 2025 | libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to ... |
| CVE-2025-24903 | HIGH | 8.5 | 0.2% | Feb 13, 2025 | libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to ... |
| CVE-2025-22480 | HIGH | 7.8 | 0.2% | Feb 13, 2025 | Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now