2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-13254HIGH8.8A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unkno...
CVE-2025-13253HIGH8.8A vulnerability was determined in projectworlds Advanced Library Management System 1.0. This affects an unknown part of ...
CVE-2025-13252HIGH7.3A vulnerability was found in shsuishang ShopSuite ModulithShop up to 45a99398cec3b7ad7ff9383694f0b53339f2d35a. Affected ...
CVE-2025-13251HIGH8.8A flaw has been found in WeiYe-Jing datax-web up to 2.1.2. Affected is an unknown function. Executing manipulation can l...
CVE-2025-13250HIGH8.8A vulnerability was detected in WeiYe-Jing datax-web up to 2.1.2. This impacts the function remove/update/pause/start/tr...
CVE-2025-13243HIGH8.8A vulnerability was found in code-projects Student Information System 2.0. Impacted is an unknown function of the file /...
CVE-2025-13239HIGH7.5A security vulnerability has been detected in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution 5. A...
CVE-2025-13238HIGH8.8A weakness has been identified in Bdtask Flight Booking Software 4. Affected by this vulnerability is an unknown functio...
CVE-2025-12482HIGH7.5The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to SQL Injection via the ‘s...
CVE-2025-13190HIGH8.8A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the ...
CVE-2025-9317HIGH8.4The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f...
CVE-2025-8386HIGH7.2The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper w...
CVE-2025-64309HIGH7.4The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut...
CVE-2025-64308HIGH7.1The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Bri...
CVE-2025-64307HIGH7.1The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized...
CVE-2025-62765HIGH8.7General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a...
CVE-2025-59780HIGH8.7General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all...
CVE-2025-55034HIGH8.8General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow a...
CVE-2025-13187HIGH7.5A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/si...
CVE-2025-63891HIGH7.5Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote u...
CVE-2025-13185HIGH7.2A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the fi...
CVE-2025-13033HIGH7.5A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient em...
CVE-2025-63680HIGH8.6Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination wi...
CVE-2025-13177HIGH8.8A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulatio...
CVE-2025-54346HIGH7.6A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now