2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27224 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the applic... |
| CVE-2025-12296 | CRITICAL | 9.8 | 7.0% | Oct 27, 2025 | A security vulnerability has been detected in D-Link DAP-2695 2.00RC13. The impacted element is the function sub_4174B0 ... |
| CVE-2025-12294 | CRITICAL | 9.8 | 0.3% | Oct 27, 2025 | A security flaw has been discovered in SourceCodester Point of Sales 1.0. Impacted is an unknown function of the file /d... |
| CVE-2025-12293 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in SourceCodester Point of Sales 1.0. This issue affects some unknown processing of the f... |
| CVE-2025-12292 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in SourceCodester Point of Sales 1.0. This vulnerability affects unknown code of the file... |
| CVE-2025-34292 | CRITICAL | 9.4 | 0.5% | Oct 27, 2025 | Rox, the software running BeWelcome, contains a PHP object injection vulnerability resulting from deserialization of unt... |
| CVE-2025-61481 | CRITICAL | 10 | 0.3% | Oct 27, 2025 | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by de... |
| CVE-2025-60291 | CRITICAL | 9.1 | 0.3% | Oct 27, 2025 | An issue was discovered in eTimeTrackLite Web thru 12.0 (20250704). There is a permission control flaw that allows unaut... |
| CVE-2025-12273 | CRITICAL | 9.8 | 0.9% | Oct 27, 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Affected is the function fromwebExcptypemanFilter of the file /gof... |
| CVE-2025-41009 | CRITICAL | 9.3 | 0.3% | Oct 27, 2025 | SQL injection vulnerability in the DRED virtual campus platform. This vulnerability allows an attacker to retrieve, crea... |
| CVE-2025-12272 | CRITICAL | 9.8 | 0.7% | Oct 27, 2025 | A security flaw has been discovered in Tenda CH22 1.0.0.1. This impacts the function fromAddressNat of the file /goform/... |
| CVE-2025-12271 | CRITICAL | 9.8 | 0.9% | Oct 27, 2025 | A vulnerability was identified in Tenda CH22 1.0.0.1. This affects the function fromRouteStatic of the file /goform/Rout... |
| CVE-2025-12268 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability has been found in LearnHouse up to 98dfad76aad70711a8113f6c1fdabfccf10509ca. Impacted is an unknown func... |
| CVE-2025-59461 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt ser... |
| CVE-2025-12265 | CRITICAL | 9.8 | 1.0% | Oct 27, 2025 | A weakness has been identified in Tenda CH22 1.0.0.1. Affected by this issue is the function fromVirtualSer of the file ... |
| CVE-2025-12257 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some u... |
| CVE-2025-12253 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-12240 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCf... |
| CVE-2025-12239 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCf... |
| CVE-2025-12237 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function ... |
| CVE-2025-12232 | CRITICAL | 9.8 | 4.6% | Oct 27, 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter ... |
| CVE-2025-12226 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house... |
| CVE-2025-12215 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_su... |
| CVE-2025-12211 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | A security flaw has been discovered in Tenda O3 1.0.0.10(2478). Affected by this issue is the function SetValue/GetValue... |
| CVE-2025-12210 | CRITICAL | 9.8 | 1.0% | Oct 27, 2025 | A vulnerability was identified in Tenda O3 1.0.0.10(2478). Affected by this vulnerability is the function SetValue/GetVa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now