2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71399HIGH8.6Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize...
CVE-2025-15675MEDIUM4.8The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor...
CVE-2025-71404MEDIUM5.1better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ...
CVE-2025-71403HIGH7.1better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ...
CVE-2025-71402LOW2better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou...
CVE-2025-14073MEDIUM5.3The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur...
CVE-2025-14469MEDIUM4.3The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ...
CVE-2025-15669MEDIUM4.8The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren...
CVE-2025-69948CRITICAL9.8SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1.
CVE-2025-69946CRITICAL9.8SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr...
CVE-2025-62347MEDIUM4.3HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and...
CVE-2025-67651MEDIUM6.9A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ...
CVE-2025-67650HIGH8.6An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio...
CVE-2025-67649CRITICAL9.3A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input ...
CVE-2025-69947CRITICAL9.8SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.
CVE-2025-69941CRITICAL9.8SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.
CVE-2025-69938CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.
CVE-2025-69937CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete...
CVE-2025-69936CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.
CVE-2025-69935CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th...
CVE-2025-69934CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.
CVE-2025-69933CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.
CVE-2025-69931CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.
CVE-2025-69930CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.
CVE-2025-65342MEDIUM6.1code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now