2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-1173 | HIGH | 7.2 | 0.6% | Feb 11, 2025 | A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affe... |
| CVE-2025-1172 | HIGH | 8.8 | 0.5% | Feb 11, 2025 | A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affe... |
| CVE-2025-1143 | HIGH | 8.4 | 0.2% | Feb 11, 2025 | Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in ... |
| CVE-2025-1166 | HIGH | 8.8 | 0.5% | Feb 11, 2025 | A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vuln... |
| CVE-2025-25243 | HIGH | 8.6 | 0.7% | Feb 11, 2025 | SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a public... |
| CVE-2025-24876 | HIGH | 8.1 | 0.5% | Feb 11, 2025 | The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an aut... |
| CVE-2025-24868 | HIGH | 7.1 | 0.2% | Feb 11, 2025 | The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA X... |
| CVE-2025-23193 | HIGH | 7.5 | 0.3% | Feb 11, 2025 | SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respon... |
| CVE-2025-1165 | HIGH | 7.3 | 0.4% | Feb 11, 2025 | A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUp... |
| CVE-2025-1163 | HIGH | 7.5 | 0.4% | Feb 11, 2025 | A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerabil... |
| CVE-2025-1162 | HIGH | 7.5 | 0.5% | Feb 10, 2025 | A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part... |
| CVE-2025-24970 | HIGH | 7.5 | 2.0% | Feb 10, 2025 | Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final... |
| CVE-2025-1156 | HIGH | 7.3 | 0.4% | Feb 10, 2025 | A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unkno... |
| CVE-2025-21693 | HIGH | 7.8 | 0.2% | Feb 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: mm: zswap: properly synchronize freeing resources d... |
| CVE-2025-21692 | HIGH | 7.8 | 0.6% | Feb 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB Indexing Haowei Yan ... |
| CVE-2025-21687 | HIGH | 7.8 | 0.2% | Feb 10, 2025 | In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write sysca... |
| CVE-2025-1193 | HIGH | 8.1 | 0.4% | Feb 10, 2025 | Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and ... |
| CVE-2025-1099 | HIGH | 7 | 0.2% | Feb 10, 2025 | This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmwar... |
| CVE-2025-1117 | HIGH | 7.3 | 0.4% | Feb 8, 2025 | A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart. This affects an un... |
| CVE-2025-1116 | HIGH | 7.3 | 0.4% | Feb 8, 2025 | A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on O... |
| CVE-2025-24366 | HIGH | 7.5 | 0.7% | Feb 7, 2025 | SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands vi... |
| CVE-2025-1108 | HIGH | 8.6 | 0.2% | Feb 7, 2025 | Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticate... |
| CVE-2025-25159 | HIGH | 7.1 | 0.2% | Feb 7, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robert_kolatzek WP... |
| CVE-2025-25156 | HIGH | 7.1 | 0.1% | Feb 7, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This ... |
| CVE-2025-25155 | HIGH | 7.5 | 0.5% | Feb 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in efreja Music Sheet Viewe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now