2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-1173HIGH7.2A vulnerability, which was classified as critical, was found in 1000 Projects Bookstore Management System 1.0. This affe...
CVE-2025-1172HIGH8.8A vulnerability, which was classified as critical, has been found in 1000 Projects Bookstore Management System 1.0. Affe...
CVE-2025-1143HIGH8.4Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in ...
CVE-2025-1166HIGH8.8A vulnerability has been found in SourceCodester Food Menu Manager 1.0 and classified as critical. Affected by this vuln...
CVE-2025-25243HIGH8.6SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a public...
CVE-2025-24876HIGH8.1The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an aut...
CVE-2025-24868HIGH7.1The User Account and Authentication service (UAA) for SAP HANA extended application services, advanced model (SAP HANA X...
CVE-2025-23193HIGH7.5SAP NetWeaver Server ABAP allows an unauthenticated attacker to exploit a vulnerability that causes the server to respon...
CVE-2025-1165HIGH7.3A vulnerability, which was classified as critical, was found in Lumsoft ERP 8. Affected is the function DoUpload/DoWebUp...
CVE-2025-1163HIGH7.5A vulnerability classified as critical was found in code-projects Vehicle Parking Management System 1.0. This vulnerabil...
CVE-2025-1162HIGH7.5A vulnerability classified as critical has been found in code-projects Job Recruitment 1.0. This affects an unknown part...
CVE-2025-24970HIGH7.5Netty, an asynchronous, event-driven network application framework, has a vulnerability starting in version 4.1.91.Final...
CVE-2025-1156HIGH7.3A vulnerability has been found in Pix Software Vivaz 6.0.10 and classified as critical. This vulnerability affects unkno...
CVE-2025-21693HIGH7.8In the Linux kernel, the following vulnerability has been resolved: mm: zswap: properly synchronize freeing resources d...
CVE-2025-21692HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net: sched: fix ets qdisc OOB Indexing Haowei Yan ...
CVE-2025-21687HIGH7.8In the Linux kernel, the following vulnerability has been resolved: vfio/platform: check the bounds of read/write sysca...
CVE-2025-1193HIGH8.1Improper host validation in the certificate validation component in Devolutions Remote Desktop Manager on 2024.3.19 and ...
CVE-2025-1099HIGH7This vulnerability exists in Tapo C500 Wi-Fi camera due to hard-coded RSA private key embedded within the device firmwar...
CVE-2025-1117HIGH7.3A vulnerability, which was classified as critical, was found in CoinRemitter 0.0.1/0.0.2 on OpenCart. This affects an un...
CVE-2025-1116HIGH7.3A vulnerability, which was classified as critical, has been found in Dreamvention Live AJAX Search Free up to 1.0.6 on O...
CVE-2025-24366HIGH7.5SFTPGo is an open source, event-driven file transfer solution. SFTPGo supports execution of a defined set of commands vi...
CVE-2025-1108HIGH8.6Insufficient data authenticity verification vulnerability in Janto, versions prior to r12. This allows an unauthenticate...
CVE-2025-25159HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in robert_kolatzek WP...
CVE-2025-25156HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Stanko Metodiev Quote Comments quote-comments allows Stored XSS.This ...
CVE-2025-25155HIGH7.5Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in efreja Music Sheet Viewe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now