CVEs from 2025

8,971 normalized CVEs published or assigned in this year.

Total
8,971
critical
critical 1,368
high
high 2,067
medium
medium 2,068
low
low 204
% Critical
15.2%
% with KEV
2.0%
% with exploit
2.8%

Top products

  • i-educar 80
  • office_long_term_servicing_channel 35
  • office 34
  • best_salon_management_system 33
  • apartment_management_system 30
  • gcp 29
  • inventory_management_system 28
  • online_learning_management_system 21
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-32491 critical 9.8 9.8 1y ago Incorrect Privilege Assignment vulnerability in Rankology Rankology SEO – On-site SEO rankology-seo-all-in-one-seo-analytics allows Privilege Escalation.This issue affects Rankology SEO – On-site SEO…
CVE-2025-25373 critical 9.8 9.8 1y ago The Memory Management Module of NASA cFS (Core Flight System) Aquila has insecure permissions, which can be exploited to gain an RCE on the platform.
CVE-2025-2655 critical 9.8 9.8 1y ago A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation …
CVE-2025-26966 critical 9.8 9.8 1y ago Authentication Bypass Using an Alternate Path or Channel vulnerability in Aldo Latino PrivateContent private-content.This issue affects PrivateContent: from n/a through <= 8.11.5.
CVE-2025-24607 critical 9.8 9.8 1y ago Missing Authorization vulnerability in Northern Beaches Websites IdeaPush ideapush allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects IdeaPush: from n/a throug…
CVE-2025-55754 critical 9.6 9.6 19d ago Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Win…
CVE-2025-11022 critical 9.6 9.6 6mo ago Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery.  This CSRF vulnerability resulting in Command Injection has been identified. Thi…
CVE-2025-60156 critical 9.6 9.6 8mo ago Cross-Site Request Forgery (CSRF) vulnerability in webandprint AR For WordPress ar-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects AR For WordPress: from n/a through <= 8.3…
CVE-2025-7743 critical 9.6 9.6 9mo ago Cleartext Transmission of Sensitive Information vulnerability in Dolusoft Omaspot allows Interception, Privilege Escalation. This issue affects Omaspot: before 12.09.2025.
CVE-2025-30967 critical 9.6 9.6 1y ago Cross-Site Request Forgery (CSRF) vulnerability in NotFound WPJobBoard allows Upload a Web Shell to a Web Server. This issue affects WPJobBoard: from n/a through n/a.
CVE-2025-20234 critical 9.5 A vulnerability in Universal Disk Format (UDF) processing of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnera…
CVE-2025-20260 critical 9.5 A vulnerability in the PDF scanning processes of ClamAV could allow an unauthenticated, remote attacker to cause a buffer overflow condition, cause a denial of service (DoS) condition, or execute arb…
CVE-2025-14931 critical 9.5 6mo ago Hugging Face smolagents: Unsafe deserialization in Remote Python Executor leads to RCE
CVE-2025-47151 critical 9.5 7mo ago RHSA-2025:21628: lasso security update (Critical)
CVE-2025-55747 critical 9.5 9mo ago XWiki configuration files can be accessed through the webjars API
CVE-2025-8077 critical 9.5 9mo ago NeuVector admin account has insecure default password
CVE-2025-30405 critical 9.5 10mo ago ExecuTorch integer overflow vulnerability
CVE-2025-30404 critical 9.5 10mo ago ExecuTorch integer overflow vulnerability
CVE-2025-54951 critical 9.5 10mo ago ExecuTorch vulnerable to Heap-based Buffer Overflow
CVE-2025-54950 critical 9.5 10mo ago ExecuTorch out-of-bounds access vulnerability
CVE-2025-54949 critical 9.5 10mo ago ExecuTorch heap buffer overflow vulnerability
CVE-2025-69614 critical 9.4 9.4 3mo ago Incorrect Access Control via activation token reuse on the password-reset endpoint allowing unauthorized password resets and full account takeover. Affected Product: Deutsche Telekom AG Telekom Accou…
CVE-2025-8668 critical 9.4 9.4 4mo ago Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd…
CVE-2025-4319 critical 9.4 9.4 4mo ago Improper Restriction of Excessive Authentication Attempts, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Birebirsoft Software and Technology Solutions Sufirmam allows Brute…
CVE-2025-8220 critical 9.4 9.4 11mo ago A vulnerability has been found in Engeman Web up to 12.0.0.2. The affected element is an unknown function of the file /Login/RecoveryPass of the component Password Recovery Page. The manipulation of …
CVE-2025-27851 critical 9.3 9.3 24d ago The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including…
CVE-2025-49055 critical 9.3 9.3 5mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in kamleshyadav WP Lead Capturing Pages wp-lead-capture allows Blind SQL Injection.This issue affect…
CVE-2025-32303 critical 9.3 9.3 5mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla WPCHURCH allows Blind SQL Injection.This issue affects WPCHURCH: from n/a through 2.7.0.
CVE-2025-39484 critical 9.3 9.3 5mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Waituk Entrada allows SQL Injection.This issue affects Entrada: from n/a through 5.7.7.
CVE-2025-68865 critical 9.3 9.3 5mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility Global infility-global allows SQL Injection.This issue affects Infility Global:…
CVE-2025-30633 critical 9.3 9.3 5mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Native Shopping Recommendations allows SQL Injection.This issue affects Amazon Nat…
CVE-2025-58951 critical 9.3 9.3 6mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartcms Advance Seat Reservation Management for WooCommerce scw-seat-reservation allows SQL Inje…
CVE-2025-48089 critical 9.3 9.3 7mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Education WordPress Theme | HiStudy histudy allows SQL Injection.This issue affect…
CVE-2025-59557 critical 9.3 9.3 8mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThemeMove Learts Addons learts-addons allows SQL Injection.This issue affects Learts Addons: from…
CVE-2025-49931 critical 9.3 9.3 8mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Crocoblock JetSearch jet-search allows Blind SQL Injection.This issue affects JetSearch: from n/a…
CVE-2025-49915 critical 9.3 9.3 8mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozy Vision SMS Alert Order Notifications sms-alert allows SQL Injection.This issue affects SMS A…
CVE-2025-11849 critical 9.3 9.3 8mo ago Mammoth is vulnerable to Directory Traversal
CVE-2025-39496 critical 9.3 9.3 9mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Product Filter Pro allows SQL Injection.This issue affects WooBeWoo Product Filter P…
CVE-2025-52830 critical 9.3 9.3 11mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in bSecure – Your Universal Checkout bSecure – Your Universal Checkout bsecure allows Blind SQL Inje…
CVE-2025-4383 critical 9.3 9.3 1y ago Improper Restriction of Excessive Authentication Attempts vulnerability in Art-in Bilişim Teknolojileri ve Yazılım Hizm. Tic. Ltd. Şti. Wi-Fi Cloud Hotspot allows Authentication Abuse, Authentication…
CVE-2025-47573 critical 9.3 9.3 1y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Management allows Blind SQL Injection. This issue affects School Management: from…
CVE-2025-39479 critical 9.3 9.3 1y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart Notification allows Blind SQL Injection. This issue affects Smart Notification:…
CVE-2025-39389 critical 9.3 9.3 1y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Solid Plugins AnalyticsWP allows SQL Injection.This issue affects AnalyticsWP: from n/a through 2…
CVE-2025-32643 critical 9.3 9.3 1y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPGYM allows Blind SQL Injection. This issue affects WPGYM: from n/a through 65.0.
CVE-2025-47657 critical 9.3 9.3 1y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Productive Minds Productive Commerce productive-commerce allows SQL Injection.This issue affects …
CVE-2025-30622 critical 9.3 9.3 1y ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in torsteino PostMash postmash-custom allows SQL Injection.This issue affects PostMash: from n/a thr…
CVE-2025-41268 critical 9.1 9.1 8d ago Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated att…
CVE-2025-40949 critical 9.1 9.1 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2025-69690 critical 9.1 9.1 1mo ago Netgate pfSense CE 2.7.2 allows code execution by using the module installer with a backup file with a serialized PHP object containing the post_reboot_commands property. NOTE: the Supplier disputes …
CVE-2025-59852 critical 9.1 9.1 1mo ago HCL DFXAnalytics is affected by an Insufficient Transport Layer Protection vulnerability where data is transmitted over the network without encryption, which could allow an attacker to compromise t…
CVE-2025-14543 critical 9.1 9.1 1mo ago Improper Restriction of XML External Entity Reference vulnerability in Connext Professional (Core Libraries) allows Serialized Data External Linking.This issue affects Connext Professional: from 7.4.…
CVE-2025-69615 critical 9.1 9.1 3mo ago Incorrect Access Control via missing 2FA rate-limiting allowing unlimited brute-force retries and full MFA bypass with no user interaction required. Affected Product: Deutsche Telekom AG Telekom Acco…
CVE-2025-11158 critical 9.1 9.1 3mo ago Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6, including 9.3.x and 8.3.x, do not restrict Groovy scripts in new PRPT reports published by users, allowing insertion of …
CVE-2025-1928 critical 9.1 9.1 6mo ago Improper Restriction of Excessive Authentication Attempts vulnerability in Restajet Information Technologies Inc. Online Food Delivery System allows Password Recovery Exploitation. This issue affect…
CVE-2025-14520 critical 9.1 9.1 6mo ago A weakness has been identified in baowzh hfly up to 638ff9abe9078bc977c132b37acbe1900b63491c. Impacted is an unknown function of the file /admin/index.php/datafile/delfile. This manipulation of the a…
CVE-2025-11631 critical 9.1 9.1 8mo ago A vulnerability was determined in RainyGao DocSys up to 2.02.36. Affected by this vulnerability is an unknown functionality of the file /Doc/deleteDoc.do. Executing manipulation of the argument path …
CVE-2025-9004 critical 9.1 9.1 10mo ago A vulnerability was found in mtons mblog up to 3.5.0. This issue affects some unknown processing of the file /settings/password. The manipulation leads to improper restriction of excessive authentica…
CVE-2025-8729 critical 9.1 9.1 10mo ago A vulnerability has been found in MigoXLab LMeterX 1.2.0 and classified as critical. Affected by this vulnerability is the function process_cert_files of the file backend/service/upload_service.py. T…
CVE-2025-22871 critical 9.1 9.1 10mo ago Moderate: git-lfs security update
CVE-2025-49794 critical 9.1 9.1 11mo ago A use-after-free vulnerability was found in libxml2. This issue occurs when parsing XPath elements under certain circumstances when the XML schematron has the <sch:name path="..."/> schema elements. …
CVE-2025-49796 critical 9.1 9.1 11mo ago A vulnerability was found in libxml2. Processing certain sch:name elements from the input XML file can trigger a memory corruption issue. This flaw allows an attacker to craft a malicious XML input f…
CVE-2025-48267 critical 9.1 9.1 1y ago Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allows Path Traversal. This issue affects WP Pipes: from n/a through 1.4.2.
CVE-2025-2691 critical 9.1 9.1 1y ago nossrf Server-Side Request Forgery (SSRF)
CVE-2025-62023 critical 9.0 9.0 8mo ago Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.
CVE-2025-8535 critical 9.0 9.0 10mo ago A vulnerability, which was classified as problematic, has been found in cronoh NanoVault up to 1.2.1. This issue affects the function executeJavaScript of the file /main.js of the component xrb URL H…
CVE-2025-8264 critical 9.0 9.0 10mo ago z-push/z-push-dev SQL Injection Vulnerability
CVE-2025-31916 critical 9.0 9.0 1y ago Unrestricted Upload of File with Dangerous Type vulnerability in joy2012bd JP Students Result Management System Premium allows Upload a Web Shell to a Web Server. This issue affects JP Students Resul…
CVE-2025-2311 critical 9.0 9.0 1y ago Incorrect Use of Privileged APIs, Cleartext Transmission of Sensitive Information, Insufficiently Protected Credentials vulnerability in Sechard Information Technologies SecHard allows Authentication…
CVE-2025-24813 medium 8.0 1y ago Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apach…
CVE-2025-4123 medium 6.1 7.1 1y ago Important: grafana security update
CVE-2025-15653 medium 6.8 6.8 4d ago Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to compromise softwa…
CVE-2025-40948 medium 6.8 6.8 26d ago A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1…
CVE-2025-4397 medium 6.8 6.8 1mo ago Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.
CVE-2025-4386 medium 6.8 6.8 1mo ago Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​
CVE-2025-57175 medium 6.8 6.8 2mo ago Siklu EtherHaul 8010 siklu-uimage-nxp-enc-10_6_2-18707-ea552dc00b devices have a static root password.
CVE-2025-13913 medium 6.8 6.8 3mo ago A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.
CVE-2025-7708 medium 6.8 6.8 4mo ago Insertion of Sensitive Information Into Sent Data vulnerability in Atlas Educational Software Industry Ltd. Co. K12net allows Communication Channel Manipulation. This issue affects k12net: through 0…
CVE-2025-11647 medium 6.8 6.8 8mo ago A flaw has been found in Tomofun Furbo 360 and Furbo Mini. This issue affects some unknown processing of the component GATT Service. This manipulation of the argument DeviceToken causes information d…
CVE-2025-8762 medium 6.8 6.8 10mo ago A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the component UART Interface. The manipulation leads to improper physical access contro…
CVE-2025-8231 medium 6.8 6.8 10mo ago A vulnerability, which was classified as critical, has been found in D-Link DIR-890L up to 111b04. This issue affects some unknown processing of the file rgbin of the component UART Port. The manipul…
CVE-2025-6534 medium 6.8 6.8 1y ago A vulnerability, which was classified as problematic, was found in xxyopen/201206030 novel-plus up to 5.1.3. This affects the function remove of the file novel-admin/src/main/java/com/java2nb/common/…
CVE-2025-26465 medium 6.8 6.8 1y ago A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occur…
CVE-2025-59614 medium 6.7 6.7 5d ago Memory Corruption when sending random number generator command with insufficient output buffer size.
CVE-2025-59613 medium 6.7 6.7 5d ago Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
CVE-2025-59612 medium 6.7 6.7 5d ago Memory corruption in windows drivers while sending incorrect trusted application request
CVE-2025-59611 medium 6.7 6.7 5d ago Memory corruption in diagnostic services due to absence of input validation
CVE-2025-53870 medium 6.7 6.7 25d ago An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5, FortiAP 7.2 all versi…
CVE-2025-53680 medium 6.7 6.7 25d ago An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, FortiAP 7.4.0 through 7.4.5…
CVE-2025-57851 medium 6.7 6.7 2mo ago A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during b…
CVE-2025-66237 medium 6.7 6.7 6mo ago DCIM dcTrack platforms utilize default and hard-coded credentials for access. An attacker could use these credentials to administer the database, escalate privileges on the platform or execute system…
CVE-2025-11666 medium 6.7 6.7 8mo ago A flaw has been found in Tenda RP3 Pro up to 22.5.7.93. This impacts an unknown function of the file force_upgrade.sh of the component Firmware Update Handler. Executing manipulation of the argument …
CVE-2025-8886 medium 6.7 6.7 8mo ago Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Sys…
CVE-2025-46641 medium 6.6 6.6 2mo ago Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 8.4 through 8.5 contain an improper authentication vulnerability. A high privileged attacker with r…
CVE-2025-46836 medium 6.6 6.6 1y ago net-tools is a collection of programs that form the base set of the NET-3 networking distribution for the Linux operating system. Inn versions up to and including 2.10, the Linux network utilities (l…
CVE-2025-5090 medium 6.5 6.5 1d ago CVX is not resilient to unexpected messages from a connected switch. This leads to agent crashes on CVX causing instability in the CVX cluster. An attacker could use this behavior to create a denial …
CVE-2025-5089 medium 6.5 6.5 1d ago In a CVX cluster, an EOS switch connected to a CVX server is not resilient to certain malformed messages received from the connected CVX server. Similarly, the CVX server is not resilient to certain …
CVE-2025-59174 medium 6.5 6.5 1d ago Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.
CVE-2025-70101 medium 6.5 6.5 3d ago An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 files…
CVE-2025-52766 medium 6.5 6.5 5d ago Missing Authorization vulnerability in Printeers Printeers Print & Ship allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Printeers Print & Ship: from n/a t…
CVE-2025-59601 medium 6.5 6.5 5d ago Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.