2025 CVE Vulnerabilities

45,266 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-5121CRITICAL9.9An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A ...
CVE-2025-52484LOW2.7RISC Zero is a general computing platform based on zk-STARKs and the RISC-V microarchitecture. Due to a missing constrai...
CVE-2025-46158MEDIUM6.2An issue in redoxOS kernel before commit 5d41cd7c allows a local attacker to cause a denial of service via the `setitime...
CVE-2025-2443MEDIUM6.1An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass...
CVE-2025-6355CRITICAL9.8A vulnerability has been found in SourceCodester Online Hotel Reservation System 1.0 and classified as critical. This vu...
CVE-2025-6354CRITICAL9.8A vulnerability, which was classified as critical, has been found in code-projects Online Shoe Store 1.0. Affected by th...
CVE-2025-6353MEDIUM5.4A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability...
CVE-2025-49132CRITICAL10Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.jso...
CVE-2025-48059LOW2.7PowSyBl (Power System Blocks) is a framework to build power system oriented software. In com.powsybl:powsybl-iidm-criter...
CVE-2025-44635CRITICAL9.8There are multiple unauthorized remote command execution vulnerabilities in the H3C ER2200G2, ERG2-450W, ERG2-1200W, ERG...
CVE-2025-6352CRITICAL9.1A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an un...
CVE-2025-6351CRITICAL9.8A vulnerability was found in itsourcecode Employee Record Management System 1.0. It has been rated as critical. This iss...
CVE-2025-6347MEDIUM5.4A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This v...
CVE-2025-6193MEDIUM5.9A command injection vulnerability was discovered in the TrustyAI Explainability toolkit. Arbitrary commands placed in ce...
CVE-2025-5416LOW2.7A vulnerability has been identified in Keycloak that could lead to unauthorized information disclosure. While it require...
CVE-2025-45890CRITICAL9.8Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via th...
CVE-2025-45331HIGH7.5brplot v420.69.1 contains a Null Pointer Dereference (NPD) vulnerability in the br_dagens_handle_once function of its da...
CVE-2025-44203HIGH7.5In HotelDruid 3.0.0 and 3.0.7, the unauthenticated database-setup endpoint creadb.php can be reached before setup is com...
CVE-2025-6346CRITICAL9.8A vulnerability was found in SourceCodester Advance Charity Management System 1.0. It has been classified as critical. T...
CVE-2025-6345MEDIUM5.4A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is ...
CVE-2025-52825HIGH8.8Cross-Site Request Forgery (CSRF) vulnerability in Rameez Iqbal Real Estate Manager real-estate-manager allows Privilege...
CVE-2025-52822HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WP R...
CVE-2025-52821HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in thanhtungtnt Video...
CVE-2025-52802HIGH7.5Missing Authorization vulnerability in enguerranws Import YouTube videos as WP Posts import-youtube-videos-as-wp-post al...
CVE-2025-52795HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in aharonyan WP Front User Submit / Front Editor front-editor allows Cro...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now