2025 CVE Vulnerabilities

45,269 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-22486HIGH8.8An improper certificate validation vulnerability has been reported to affect File Station 5. If exploited, the vulnerabi...
CVE-2025-22484HIGH7.1An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r...
CVE-2025-22482HIGH8.1A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the ...
CVE-2025-22481HIGH8.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If exploited, the ...
CVE-2025-5782MEDIUM6.3A vulnerability, which was classified as critical, has been found in PHPGurukul Employee Record Management System 1.3. A...
CVE-2025-5780HIGH7.5A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. Affected by ...
CVE-2025-5779HIGH7.5A vulnerability has been found in code-projects Patient Record Management System 1.0 and classified as critical. Affecte...
CVE-2025-41646CRITICAL9.8An unauthorized remote attacker can bypass the authentication of the affected software package by misusing an incorrect ...
CVE-2025-27531CRITICAL9.8Deserialization of Untrusted Data vulnerability in Apache InLong.  This issue affects Apache InLong: from 1.13.0 before...
CVE-2025-5806HIGH8Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy...
CVE-2025-5791HIGH7.1A flaw was found in the user's crate for Rust. This vulnerability allows privilege escalation via incorrect group listin...
CVE-2025-5778CRITICAL9.8A vulnerability, which was classified as critical, was found in 1000 Projects ABC Courier Management System 1.0. Affecte...
CVE-2025-38002MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: io_uring/fdinfo: grab ctx->uring_lock around io_uri...
CVE-2025-38001MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net_sched: hfsc: Address reentrant enqueue adding c...
CVE-2025-0620MEDIUM4.9A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an e...
CVE-2025-5766MEDIUM4.3A vulnerability was found in code-projects Laundry System 1.0. It has been declared as problematic. This vulnerability a...
CVE-2025-5765MEDIUM5.4A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an un...
CVE-2025-5764MEDIUM5.4A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is s...
CVE-2025-49453HIGH7.1Cross-Site Request Forgery (CSRF) vulnerability in Jatinder Pal Singh BP Profile as Homepage bp-profile-as-homepage allo...
CVE-2025-49450MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mhallmann SEPA Gir...
CVE-2025-49449MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive Regional Map of Africa interactive-map-of-...
CVE-2025-49446MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in minhlaobao Admin Notes admin-note allows Cross Site Request Forgery.T...
CVE-2025-49445MEDIUM4.3Cross-Site Request Forgery (CSRF) vulnerability in WP Map Plugins Interactive UK Regional Map interactive-uk-regional-ma...
CVE-2025-49443MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chris McCoy Bacon ...
CVE-2025-49442MEDIUM6.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mostafa Shahiri Si...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now