2025 CVE Vulnerabilities

45,295 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-34491HIGH8.8GFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attac...
CVE-2025-31651CRITICAL9.8Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely r...
CVE-2025-31650HIGH7.5Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority header...
CVE-2025-4033CRITICAL9.8A vulnerability classified as critical has been found in PHPGurukul Nipah Virus Testing Management System 1.0. Affected ...
CVE-2025-4032HIGH8.1A vulnerability was found in inclusionAI AWorld up to 8c257626e648d98d793dd9a1a950c2af4dd84c4e. It has been rated as cri...
CVE-2025-34490MEDIUM6.5GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remot...
CVE-2025-34489HIGH7.8GFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escal...
CVE-2025-4031CRITICAL9.8A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been declared as critical. This vulnera...
CVE-2025-4030CRITICAL9.8A vulnerability was found in PHPGurukul COVID19 Testing Management System 1.0. It has been classified as critical. This ...
CVE-2025-4029HIGH7.8A vulnerability was found in code-projects Personal Diary Management System 1.0 and classified as critical. Affected by ...
CVE-2025-4028CRITICAL9.8A vulnerability has been found in PHPGurukul COVID19 Testing Management System 1.0 and classified as critical. Affected ...
CVE-2025-4027CRITICAL9.8A vulnerability, which was classified as critical, was found in PHPGurukul Old Age Home Management System 1.0. Affected ...
CVE-2025-4026CRITICAL9.8A vulnerability, which was classified as critical, has been found in PHPGurukul Nipah Virus Testing Management System 1....
CVE-2025-46614LOW3.3In Snowflake ODBC Driver before 3.7.0, in certain code paths, the Driver logged the whole SQL query at the INFO level, a...
CVE-2025-43857MEDIUM6.5Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.5.7, 0.4....
CVE-2025-43854MEDIUM6.1DIFY is an open-source LLM app development platform. Prior to version 1.3.0, a clickjacking vulnerability was found in t...
CVE-2025-4025CRITICAL9.8A vulnerability classified as critical was found in itsourcecode Placement Management System 1.0. Affected by this vulne...
CVE-2025-4024CRITICAL9.8A vulnerability classified as critical has been found in itsourcecode Placement Management System 1.0. Affected is an un...
CVE-2025-25776MEDIUM5Cross-Site Scripting (XSS) vulnerability exists in the User Registration and User Profile features of Codeastro Bus Tick...
CVE-2025-23377LOW3.4Dell PowerProtect Data Manager Reporting, version(s) 19.17, 19.18 contain(s) an Improper Encoding or Escaping of Output ...
CVE-2025-23376MEDIUM4.4Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Speci...
CVE-2025-23375HIGH7.8Dell PowerProtect Data Manager Reporting, version(s) 19.17, contain(s) an Incorrect Use of Privileged APIs vulnerability...
CVE-2025-4023CRITICAL9.8A vulnerability was found in itsourcecode Placement Management System 1.0. It has been rated as critical. This issue aff...
CVE-2025-4022HIGH8.8A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affe...
CVE-2025-4021HIGH7.5A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Thi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now