2025 CVE Vulnerabilities

45,296 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-22373HIGH8.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SicommNet B...
CVE-2025-22372CRITICAL9.3Insufficiently Protected Credentials vulnerability in SicommNet BASEC on SaaS allows Password Recovery. Passwords are ei...
CVE-2025-22371CRITICAL9.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SicommNet BASEC (S...
CVE-2025-3571MEDIUM6.3A vulnerability was found in Fannuo Enterprise Content Management System 凡诺企业网站管理系统 1.1/4.0. It has been declared as cri...
CVE-2025-3570MEDIUM6.1A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This af...
CVE-2025-32930Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA.
CVE-2025-32914HIGH7.4A flaw was found in libsoup, where the soup_multipart_new_from_message() function is vulnerable to an out-of-bounds read...
CVE-2025-32912MEDIUM6.5A flaw was found in libsoup, where SoupAuthDigest is vulnerable to a NULL pointer dereference. The HTTP server may cause...
CVE-2025-32910MEDIUM6.5A flaw was found in libsoup, where soup_auth_digest_authenticate() is vulnerable to a NULL pointer dereference. This iss...
CVE-2025-32909MEDIUM5.3A flaw was found in libsoup. SoupContentSniffer may be vulnerable to a NULL pointer dereference in the sniff_mp4 functio...
CVE-2025-2475MEDIUM5.4Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to invalidate the cache when a user accoun...
CVE-2025-2424MEDIUM4.3Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark...
CVE-2025-2161MEDIUM6.1Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
CVE-2025-2160MEDIUM6.1Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
CVE-2025-3569MEDIUM6.3A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0 and classified as critical. Affected by this is...
CVE-2025-3568MEDIUM5.4A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerab...
CVE-2025-32913HIGH7.5A flaw was found in libsoup, where the soup_message_headers_get_content_disposition() function is vulnerable to a NULL p...
CVE-2025-32908HIGH7.5A flaw was found in libsoup. The HTTP/2 server in libsoup may not fully validate the values of pseudo-headers :scheme, :...
CVE-2025-32907MEDIUM5.3A flaw was found in libsoup. The implementation of HTTP range requests is vulnerable to a resource consumption attack. T...
CVE-2025-32906HIGH7.5A flaw was found in libsoup, where the soup_headers_parse_request() function may be vulnerable to an out-of-bound read. ...
CVE-2025-3567MEDIUM5.3A vulnerability, which was classified as problematic, was found in veal98 小牛肉 Echo 开源社区系统 4.2. Affected is the function ...
CVE-2025-3566HIGH7.3A vulnerability, which was classified as critical, has been found in veal98 小牛肉 Echo 开源社区系统 4.2. This issue affects the ...
CVE-2025-3565HIGH7.2A vulnerability classified as critical was found in huanfenz/code-projects StudentManager 1.0. This vulnerability affect...
CVE-2025-3564MEDIUM6.5A vulnerability classified as problematic has been found in huanfenz/code-projects StudentManager up to 1.0. This affect...
CVE-2025-3563HIGH7.2A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now