2025 CVE Vulnerabilities

45,143 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-12120HIGH7.3Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, with...
CVE-2025-62730HIGH8.8SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to...
CVE-2025-62294HIGH7.5SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recov...
CVE-2025-41075HIGH7.5Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. Th...
CVE-2025-41074HIGH7.5Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. ...
CVE-2025-40601HIGH7.5A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to ca...
CVE-2025-13468HIGH8.1A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_fo...
CVE-2025-13435HIGH8.1A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of ...
CVE-2025-13434HIGH7.5A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file H...
CVE-2025-13433HIGH7.3A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the...
CVE-2025-11676HIGH7.1Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated...
CVE-2025-0645HIGH7.2Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Lt...
CVE-2025-0643HIGH7.2Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Comm...
CVE-2025-13423HIGH7.2A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function ...
CVE-2025-11001HIGH7.87-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke...
CVE-2025-63719HIGH7.3Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter use...
CVE-2025-63371HIGH7.5Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file p...
CVE-2025-65103HIGH8.8OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an ...
CVE-2025-63932HIGH7.3D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary...
CVE-2025-51663HIGH7.5A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based ...
CVE-2025-51661HIGH7.5A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is co...
CVE-2025-65094HIGH8.8WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their pr...
CVE-2025-65034HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerabil...
CVE-2025-65033HIGH8.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma...
CVE-2025-65030HIGH7.1Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now