2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-54404HIGH8.8Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec...
CVE-2025-54403HIGH8.8Multiple OS command injection vulnerabilities exist in the swctrl functionality of Planet WGR-500 v1.3411b190912. A spec...
CVE-2025-54402HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-54401HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-54400HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-54399HIGH8.8Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b19...
CVE-2025-53476MEDIUM5.3A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c...
CVE-2025-50505HIGH7.8Clash Verge Rev thru 2.2.3 (fixed in 2.3.0) forces the installation of system services(clash-verge-service) by default a...
CVE-2025-48826HIGH8.8A format string vulnerability exists in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially craf...
CVE-2025-37728MEDIUM5.4Insufficiently Protected Credentials in the Crowdstrike connector can lead to Crowdstrike credentials being leaked. A ma...
CVE-2025-25009MEDIUM5.4Improper Neutralization of Input During Web Page Generation in Kibana can lead to Stored XSS via case file upload.
CVE-2025-11397CRITICAL9.8A security flaw has been discovered in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an ...
CVE-2025-40889HIGH8.1A path traversal vulnerability was discovered in the Time Machine functionality due to missing validation of two input p...
CVE-2025-40888MEDIUM6.5A SQL Injection vulnerability was discovered in the CLI functionality due to improper validation of an input parameter. ...
CVE-2025-40887MEDIUM6.5A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter...
CVE-2025-40886HIGH8.8A SQL Injection vulnerability was discovered in the Alert functionality due to improper validation of an input parameter...
CVE-2025-40885MEDIUM6.5A SQL Injection vulnerability was discovered in the Smart Polling functionality due to improper validation of an input p...
CVE-2025-40676MEDIUM5.3Insecure Direct Object Reference (IDOR) in Negotiator v3.15.2 from Biobanking and Biomolecular Resources - European Rese...
CVE-2025-40649MEDIUM5.1Stored Cross-Site Scripting (XSS) in Biobanking and Biomolecular Resources Negotiator v3.15.2 - European Research Infras...
CVE-2025-3719HIGH8.1An access control vulnerability was discovered in the CLI functionality due to a specific access restriction not being p...
CVE-2025-3718MEDIUM5.4A client-side path traversal vulnerability was discovered in the web management interface front-end due to missing valid...
CVE-2025-11396CRITICAL9.8A vulnerability was identified in code-projects Simple Food Ordering System 1.0. Impacted is an unknown function of the ...
CVE-2025-11390MEDIUM6.1A weakness has been identified in PHPGurukul Cyber Cafe Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-11389HIGH8.8A security flaw has been discovered in Tenda AC15 15.03.05.18. Affected is an unknown function of the file /goform/saveA...
CVE-2025-0603CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Callvision Healthc...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now