2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12257 | CRITICAL | 9.8 | 0.5% | Oct 27, 2025 | A security vulnerability has been detected in SourceCodester Online Student Result System 1.0. This issue affects some u... |
| CVE-2025-12253 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was determined in AMTT Hotel Broadband Operation System 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-12240 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | A security vulnerability has been detected in TOTOLINK A3300R 17.0.0cu.557_B20221024. This affects the function setDmzCf... |
| CVE-2025-12239 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | A weakness has been identified in TOTOLINK A3300R 17.0.0cu.557_B20221024. The impacted element is the function setDdnsCf... |
| CVE-2025-12237 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was identified in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function ... |
| CVE-2025-12232 | CRITICAL | 9.8 | 4.6% | Oct 27, 2025 | A vulnerability was detected in Tenda CH22 1.0.0.1. Affected by this vulnerability is the function fromSafeClientFilter ... |
| CVE-2025-12226 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0. Impacted is the function save_house... |
| CVE-2025-12215 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A flaw has been found in projectworlds Online Shopping System 1.0. Impacted is an unknown function of the file /login_su... |
| CVE-2025-12211 | CRITICAL | 9.8 | 0.8% | Oct 27, 2025 | A security flaw has been discovered in Tenda O3 1.0.0.10(2478). Affected by this issue is the function SetValue/GetValue... |
| CVE-2025-12210 | CRITICAL | 9.8 | 1.0% | Oct 27, 2025 | A vulnerability was identified in Tenda O3 1.0.0.10(2478). Affected by this vulnerability is the function SetValue/GetVa... |
| CVE-2025-12208 | CRITICAL | 9.8 | 0.4% | Oct 27, 2025 | A vulnerability was found in SourceCodester Best House Rental Management System 1.0. This impacts the function login2 of... |
| CVE-2025-62959 | CRITICAL | 9.1 | 0.4% | Oct 27, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-... |
| CVE-2025-12285 | CRITICAL | 9.8 | 0.3% | Oct 26, 2025 | Missing Initial Password Change.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12275 | CRITICAL | 9.8 | 0.5% | Oct 26, 2025 | Mail Configuration File Manipulation + Command Execution.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.... |
| CVE-2025-12220 | CRITICAL | 9.8 | 0.3% | Oct 25, 2025 | Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12219 | CRITICAL | 9.8 | 0.3% | Oct 25, 2025 | Vulnerable Components in Azure Access OS.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12218 | CRITICAL | 9.1 | 0.3% | Oct 25, 2025 | Weak Default Credentials.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-12217 | CRITICAL | 9.1 | 0.3% | Oct 25, 2025 | SNMP Default Community String (public).This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-62717 | CRITICAL | 9.1 | 0.4% | Oct 24, 2025 | Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification co... |
| CVE-2025-60803 | CRITICAL | 9.8 | 0.6% | Oct 24, 2025 | Antabot White-Jotter up to commit 9bcadc was discovered to contain an unauthenticated remote code execution (RCE) vulner... |
| CVE-2025-60554 | CRITICAL | 9.8 | 0.4% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60553 | CRITICAL | 9.8 | 0.4% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formS... |
| CVE-2025-60548 | CRITICAL | 9.8 | 0.4% | Oct 24, 2025 | D-Link DIR600L Ax FW116WWb01 was discovered to contain a buffer overflow via the curTime parameter in the function formL... |
| CVE-2025-12176 | CRITICAL | 9.8 | 0.3% | Oct 24, 2025 | Undocumented administrative accounts were getting created to facilitate access for applications running on board.This is... |
| CVE-2025-8536 | CRITICAL | 9.3 | 0.3% | Oct 24, 2025 | A SQL injection vulnerability has been identified in DobryCMS. Improper neutralization of input provided by user into la... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now