2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-71399 | HIGH | 8.6 | — | Aug 2, 2026 | Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize... |
| CVE-2025-15675 | MEDIUM | 4.8 | — | Aug 2, 2026 | The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor... |
| CVE-2025-71404 | MEDIUM | 5.1 | — | Aug 1, 2026 | better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the ... |
| CVE-2025-71403 | HIGH | 7.1 | — | Aug 1, 2026 | better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ... |
| CVE-2025-71402 | LOW | 2 | — | Aug 1, 2026 | better-auth versions greater than 1.3.34 and before 1.4.0 contain a vulnerability in the multi-session plugin's /sign-ou... |
| CVE-2025-14073 | MEDIUM | 5.3 | — | Aug 1, 2026 | The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur... |
| CVE-2025-14469 | MEDIUM | 4.3 | — | Aug 1, 2026 | The Theme Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-15669 | MEDIUM | 4.8 | — | Aug 1, 2026 | The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren... |
| CVE-2025-69948 | CRITICAL | 9.8 | 0.3% | Jul 31, 2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. |
| CVE-2025-69946 | CRITICAL | 9.8 | 0.3% | Jul 31, 2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr... |
| CVE-2025-62347 | MEDIUM | 4.3 | — | Jul 31, 2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and... |
| CVE-2025-67651 | MEDIUM | 6.9 | — | Jul 31, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ... |
| CVE-2025-67650 | HIGH | 8.6 | — | Jul 31, 2026 | An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio... |
| CVE-2025-67649 | CRITICAL | 9.3 | — | Jul 31, 2026 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input ... |
| CVE-2025-69947 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. |
| CVE-2025-69941 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. |
| CVE-2025-69938 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. |
| CVE-2025-69937 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete... |
| CVE-2025-69936 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. |
| CVE-2025-69935 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th... |
| CVE-2025-69934 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. |
| CVE-2025-69933 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. |
| CVE-2025-69931 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. |
| CVE-2025-69930 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. |
| CVE-2025-65342 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now