2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-3509HIGH7.2A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute...
CVE-2025-3246HIGH7.6An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allowed cross-site scr...
CVE-2025-3124MEDIUM4.3A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of...
CVE-2025-29461HIGH7.6An issue in a-blogcms 3.1.15 allows a remote attacker to obtain sensitive information via the /bid/1/admin/entry-edit/ p...
CVE-2025-29460HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Add Mycode function. NOTE: the ...
CVE-2025-29459HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Mail function. NOTE: the Suppli...
CVE-2025-29458HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. NOTE: t...
CVE-2025-29457HIGH7.6An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Import a Theme function. NOTE: ...
CVE-2025-29456MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29453MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29455MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29454MEDIUM6.5An issue in personal-management-system Personal Management System 1.4.65 allows a remote attacker to obtain sensitive in...
CVE-2025-29452HIGH7.6An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Proxy Manager component.
CVE-2025-29451HIGH7.6An issue in Seo Panel 4.11.0 allows a remote attacker to obtain sensitive information via the Mail Setting component.
CVE-2025-29450MEDIUM6.5An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the site settings comp...
CVE-2025-29449MEDIUM6.5An issue in twonav v.2.1.18-20241105 allows a remote attacker to obtain sensitive information via the link identificatio...
CVE-2025-3765HIGH8.8A vulnerability, which was classified as critical, has been found in SourceCodester Web-based Pharmacy Product Managemen...
CVE-2025-3764HIGH8.8A vulnerability classified as critical was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Thi...
CVE-2025-3763HIGH7.8A vulnerability classified as critical has been found in SourceCodester Phone Management System 1.0. This affects the fu...
CVE-2025-3762CRITICAL9.8A vulnerability was found in PCMan FTP Server 2.0.7. It has been rated as critical. Affected by this issue is some unkno...
CVE-2025-29316MEDIUM6.2An issue in DataPatrol Screenshot watermark, printing watermark agent v.3.5.2.0 allows a physically proximate attacker t...
CVE-2025-29722MEDIUM6.3A CSRF vulnerability in Commercify v1.0 allows remote attackers to perform unauthorized actions on behalf of authenticat...
CVE-2025-28101MEDIUM6.5An arbitrary file deletion vulnerability in the /post/{postTitle} component of flaskBlog v2.6.1 allows attackers to dele...
CVE-2025-28009CRITICAL9.8A SQL Injection vulnerability exists in the `u` parameter of the progress-body-weight.php endpoint of Dietiqa App v1.0.2...
CVE-2025-26269MEDIUM5.5DragonflyDB Dragonfly through 1.28.2 (fixed in 1.29.0) allows authenticated users to cause a denial of service (daemon c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now