2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12313 | CRITICAL | 9.8 | 4.0% | Oct 27, 2025 | A vulnerability has been found in D-Link DI-7001 MINI 19.09.19A1/24.04.18B1. The affected element is an unknown function... |
| CVE-2025-12309 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A weakness has been identified in code-projects Nero Social Networking Site 1.0. This affects an unknown part of the fil... |
| CVE-2025-12308 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unk... |
| CVE-2025-12307 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an un... |
| CVE-2025-12306 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the ... |
| CVE-2025-12305 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/ja... |
| CVE-2025-61385 | CRITICAL | 9.6 | 0.3% | Oct 27, 2025 | SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a spec... |
| CVE-2025-55754 | CRITICAL | 9.6 | 9.9% | Oct 27, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANS... |
| CVE-2025-12364 | CRITICAL | 9.8 | 0.3% | Oct 27, 2025 | Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12301 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown func... |
| CVE-2025-27224 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the applic... |
| CVE-2025-12296 | CRITICAL | 9.8 | 7.0% | Oct 27, 2025 | A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 ... |
| CVE-2025-12294 | CRITICAL | 9.8 | 0.3% | Oct 27, 2025 | A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /d... |
| CVE-2025-12293 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the f... |
| CVE-2025-12292 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file... |
| CVE-2025-34292 | CRITICAL | 9.4 | 0.5% | Oct 27, 2025 | Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of unt... |
| CVE-2025-61481 | CRITICAL | 10 | 0.3% | Oct 27, 2025 | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by de... |
| CVE-2025-60291 | CRITICAL | 9.1 | 0.3% | Oct 27, 2025 | An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unaut... |
| CVE-2025-12273 | CRITICAL | 9.8 | 0.9% | Oct 27, 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /gof... |
| CVE-2025-41009 | CRITICAL | 9.3 | 0.3% | Oct 27, 2025 | SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, crea... |
| CVE-2025-12272 | CRITICAL | 9.8 | 0.7% | Oct 27, 2025 | A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/... |
| CVE-2025-12271 | CRITICAL | 9.8 | 0.9% | Oct 27, 2025 | A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/Rout... |
| CVE-2025-12268 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown func... |
| CVE-2025-59461 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt ser... |
| CVE-2025-12265 | CRITICAL | 9.8 | 1.0% | Oct 27, 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Affected by this issue is the function fromVirtualSer of the file ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now