2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50584MEDIUM4.8StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Teacher module...
CVE-2025-7802MEDIUM5.4A vulnerability was found in PHPGurukul Complaint Management System 2.0 and classified as problematic. Affected by this ...
CVE-2025-7801HIGH7.3A vulnerability has been found in BossSoft CRM 6.0 and classified as critical. Affected by this vulnerability is an unkn...
CVE-2025-7800MEDIUM5.1A vulnerability classified as problematic was found in cgpandey hotelmis up to c572198e6c4780fccc63b1d3e8f3f72f825fc94e....
CVE-2025-7798MEDIUM6.3A vulnerability classified as critical has been found in Beijing Shenzhou Shihan Technology Multimedia Integrated Busine...
CVE-2025-54309CRITICAL9.8CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23, when the DMZ proxy feature is not used, mishandles AS2 validation and...
CVE-2025-52169HIGH7.1agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain a reflected cross-site scripting (XSS...
CVE-2025-52163MEDIUM6.5A Server-Side Request Forgery (SSRF) in the component TunnelServlet of agorum Software GmbH Agorum core open v11.9.2 & v...
CVE-2025-50585HIGH8.8StudentManage v1.0 was discovered to contain a SQL injection vulnerability via the component /admin/adminStudentUrl.
CVE-2025-33014MEDIUM6.1IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.4 uses a web...
CVE-2025-7797MEDIUM5.5A vulnerability was found in GPAC up to 2.4. It has been rated as problematic. Affected by this issue is the function gf...
CVE-2025-7796HIGH8.8A vulnerability, which was classified as critical, was found in Tenda FH451 1.0.0.9. This affects the function fromPptpU...
CVE-2025-7795HIGH8.8A vulnerability, which was classified as critical, has been found in Tenda FH451 1.0.0.9. Affected by this issue is the ...
CVE-2025-53901LOW3.5Wasmtime is a runtime for WebAssembly. Prior to versions 24.0.4, 33.0.2, and 34.0.2, a bug in Wasmtime's implementation ...
CVE-2025-52168MEDIUM6.5Incorrect access control in the dynawebservice component of agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 all...
CVE-2025-52166MEDIUM6.5Incorrect access control in Software GmbH Agorum core open v11.9.2 & v11.10.1 allows authenticated attackers to escalate...
CVE-2025-52164HIGH8.2Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to store credentials in plaintext.
CVE-2025-7794HIGH8.8A vulnerability classified as critical was found in Tenda FH451 1.0.0.9. Affected by this vulnerability is the function ...
CVE-2025-7793HIGH8.8A vulnerability classified as critical has been found in Tenda FH451 1.0.0.9. Affected is the function formWebTypeLibrar...
CVE-2025-7792HIGH8.8A vulnerability was found in Tenda FH451 1.0.0.9. It has been rated as critical. This issue affects the function formSaf...
CVE-2025-7783CRITICAL9.4Use of Insufficiently Random Values vulnerability in form-data allows HTTP Parameter Pollution (HPP). This vulnerability...
CVE-2025-53762CRITICAL9.9Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a networ...
CVE-2025-52162MEDIUM6.5agorum Software GmbH Agorum core open v11.9.2 & v11.10.1 was discovered to contain an XML External Entity (XXE) via the ...
CVE-2025-50586MEDIUM6.5StudentManage v1.0 was discovered to contain Cross-Site Request Forgery (CSRF).
CVE-2025-49747HIGH8.8Missing authorization in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now