2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-27224CRITICAL9.8TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the applic...
CVE-2025-12296CRITICAL9.8A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 ...
CVE-2025-12294CRITICAL9.8A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /d...
CVE-2025-12293CRITICAL9.8A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the f...
CVE-2025-12292CRITICAL9.8A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file...
CVE-2025-34292CRITICAL9.4Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of unt...
CVE-2025-61481CRITICAL10An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by de...
CVE-2025-60291CRITICAL9.1An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unaut...
CVE-2025-12273CRITICAL9.8A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /gof...
CVE-2025-41009CRITICAL9.3SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, crea...
CVE-2025-12272CRITICAL9.8A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/...
CVE-2025-12271CRITICAL9.8A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/Rout...
CVE-2025-12268CRITICAL9.8A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown func...
CVE-2025-59461CRITICAL9.8A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt ser...
CVE-2025-12265CRITICAL9.8A weakness has been identified in Tenda CH22 1.0.0.1. Affected by this issue is the function fromVirtualSer of the file ...
CVE-2025-12257CRITICAL9.8A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some u...
CVE-2025-12253CRITICAL9.8A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknow...
CVE-2025-12240CRITICAL9.8A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCf...
CVE-2025-12239CRITICAL9.8A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCf...
CVE-2025-12237CRITICAL9.8A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function ...
CVE-2025-12232CRITICAL9.8A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter ...
CVE-2025-12226CRITICAL9.8A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house...
CVE-2025-12215CRITICAL9.8A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_su...
CVE-2025-12211CRITICAL9.8A security flaw has been discovered in Tenda O3 1.0.0.10(2478). Affected by this issue is the function SetValue/GetValue...
CVE-2025-12210CRITICAL9.8A vulnerability was identified in Tenda O3 1.0.0.10(2478). Affected by this vulnerability is the function SetValue/GetVa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now