2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54404 | HIGH | 8.8 | 3.7% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec... |
| CVE-2025-54403 | HIGH | 8.8 | 3.7% | Oct 7, 2025 | Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec... |
| CVE-2025-54402 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19... |
| CVE-2025-54401 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19... |
| CVE-2025-54400 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19... |
| CVE-2025-54399 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19... |
| CVE-2025-53476 | MEDIUM | 5.3 | 0.3% | Oct 7, 2025 | A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c... |
| CVE-2025-50505 | HIGH | 7.8 | 0.2% | Oct 7, 2025 | Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default a... |
| CVE-2025-48826 | HIGH | 8.8 | 4.4% | Oct 7, 2025 | A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially craf... |
| CVE-2025-37728 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A ma... |
| CVE-2025-25009 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload. |
| CVE-2025-11397 | CRITICAL | 9.8 | 0.4% | Oct 7, 2025 | A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an ... |
| CVE-2025-40889 | HIGH | 8.1 | 0.4% | Oct 7, 2025 | A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input p... |
| CVE-2025-40888 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. ... |
| CVE-2025-40887 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter... |
| CVE-2025-40886 | HIGH | 8.8 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter... |
| CVE-2025-40885 | MEDIUM | 6.5 | 0.2% | Oct 7, 2025 | A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input p... |
| CVE-2025-40676 | MEDIUM | 5.3 | 0.2% | Oct 7, 2025 | Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Rese... |
| CVE-2025-40649 | MEDIUM | 5.1 | 0.3% | Oct 7, 2025 | Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infras... |
| CVE-2025-3719 | HIGH | 8.1 | 0.2% | Oct 7, 2025 | An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being p... |
| CVE-2025-3718 | MEDIUM | 5.4 | 0.2% | Oct 7, 2025 | A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing valid... |
| CVE-2025-11396 | CRITICAL | 9.8 | 0.4% | Oct 7, 2025 | A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the ... |
| CVE-2025-11390 | MEDIUM | 6.1 | 0.3% | Oct 7, 2025 | A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-11389 | HIGH | 8.8 | 0.7% | Oct 7, 2025 | A security flaw has been discovered in Tenda AC15 15.03.05.18. Affected is an unknown function of the file /goform/saveA... |
| CVE-2025-0603 | CRITICAL | 9.8 | 0.3% | Oct 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now