2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65341 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. |
| CVE-2025-65336 | CRITICAL | 9.8 | 0.2% | Jul 30, 2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. |
| CVE-2025-51684 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data ... |
| CVE-2025-36374 | MEDIUM | 5.5 | — | Jul 30, 2026 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile... |
| CVE-2025-0152 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2025-36431 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera... |
| CVE-2025-36298 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0... |
| CVE-2025-69949 | HIGH | 7.3 | — | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em... |
| CVE-2025-69945 | HIGH | 7.3 | — | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. |
| CVE-2025-69944 | HIGH | 7.3 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie... |
| CVE-2025-69943 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and ... |
| CVE-2025-69942 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. |
| CVE-2025-67408 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ... |
| CVE-2025-67407 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters... |
| CVE-2025-67406 | HIGH | 7.3 | — | Jul 29, 2026 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu... |
| CVE-2025-67405 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param... |
| CVE-2025-67404 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters ... |
| CVE-2025-67403 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete... |
| CVE-2025-65340 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. |
| CVE-2025-65337 | MEDIUM | 6.1 | 0.1% | Jul 29, 2026 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address ... |
| CVE-2025-14562 | LOW | 3.1 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2025-60931 | HIGH | 7.5 | — | Jul 29, 2026 | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33... |
| CVE-2025-10656 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Au... |
| CVE-2025-63913 | HIGH | 7.5 | 0.3% | Jul 27, 2026 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu... |
| CVE-2025-50455 | CRITICAL | 9.1 | 0.6% | Jul 27, 2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now