2025 CVE Vulnerabilities

45,279 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-4707CRITICAL9.8A vulnerability was found in Campcodes Sales and Inventory System 1.0. It has been rated as critical. This issue affects...
CVE-2025-4706CRITICAL9.8A vulnerability was found in projectworlds Online Examination System 1.0. It has been declared as critical. This vulnera...
CVE-2025-47580CRITICAL9.8Missing Authorization vulnerability in Rustaurius Front End Users front-end-only-users allows Exploiting Incorrectly Con...
CVE-2025-30421HIGH7.8There is a memory corruption vulnerability due to a stack-based buffer overflow in DrObjectStorage::XML_Serialize() when...
CVE-2025-30420HIGH7.8There is a memory corruption vulnerability due to an out of bounds read in Bitmap::InternalDraw() when using the SymbolE...
CVE-2025-30419HIGH7.8There is a memory corruption vulnerability due to an out of bounds read in GetSymbolBorderRectSize() when using the Symb...
CVE-2025-30418HIGH7.8There is a memory corruption vulnerability due to an out of bounds write in CheckPins() when using the SymbolEditor in N...
CVE-2025-30417HIGH7.8There is a memory corruption vulnerability due to an out of bounds write in Library!DecodeBase64() when using the Symbol...
CVE-2025-1647MEDIUM5.6Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Bootstrap a...
CVE-2025-4705CRITICAL9.8A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13. It has been classified as critical. This...
CVE-2025-4704HIGH7.3A vulnerability was found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected by t...
CVE-2025-4703CRITICAL9.8A vulnerability has been found in PHPGurukul Vehicle Parking Management System 1.13 and classified as critical. Affected...
CVE-2025-48051MEDIUM6.1powertip.ts in Lila (for Lichess) before ab0beaf allows XSS in some applications because of an innerHTML usage pattern i...
CVE-2025-48050HIGH7.5In DOMPurify through 3.2.5 before 6bc6d60, scripts/server.js does not ensure that a pathname is located under the curren...
CVE-2025-3440MEDIUM5.5IBM Security Guardium 11.5 is vulnerable to stored cross-site scripting. This vulnerability allows a privileged user to ...
CVE-2025-2570LOW2.7Mattermost versions 10.5.x <= 10.5.3, 9.11.x <= 9.11.11 fail to check `RestrictSystemAdmin` setting if user doesn't have...
CVE-2025-2527MEDIUM4.3Mattermost versions 10.5.x <= 10.5.2, 9.11.x <= 9.11.11 failed to properly verify a user's permissions when accessing gr...
CVE-2025-4702CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Vehicle Parking Management System 1.13. Affec...
CVE-2025-4701MEDIUM5.3A vulnerability, which was classified as problematic, has been found in VITA-MLLM Freeze-Omni up to 20250421. This issue...
CVE-2025-46053MEDIUM5.1A SQL Injection vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL commands and extract sensitive...
CVE-2025-44185MEDIUM5.4SourceCodester Best Employee Management System V1.0 is vulnerable to Cross Site Request Forgery (CSRF) in /admin/change_...
CVE-2025-4699CRITICAL9.8A vulnerability classified as critical was found in PHPGurukul Apartment Visitors Management System 1.0. This vulnerabil...
CVE-2025-4698CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Directory Management System 2.0. This affects an unk...
CVE-2025-4516MEDIUM5.9There is an issue in CPython when using `bytes.decode("unicode_escape", error="ignore|replace")`. If you are not using t...
CVE-2025-46052CRITICAL9.8An error-based SQL Injection (SQLi) vulnerability in WebERP v4.15.2 allows attackers to execute arbitrary SQL command an...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now