2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-69942CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1.
CVE-2025-67404CRITICAL9.8Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters ...
CVE-2025-67403CRITICAL9.8Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete...
CVE-2025-65340CRITICAL9.8kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.
CVE-2025-10656CRITICAL9.8The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Au...
CVE-2025-50455CRITICAL9.1SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp...
CVE-2025-71389CRITICAL10Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio...
CVE-2025-50329CRITICAL9.8An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec...
CVE-2025-66390CRITICAL9.8In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ...
CVE-2025-71392CRITICAL9.4SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the...
CVE-2025-51677CRITICAL9.1An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12...
CVE-2025-65720CRITICAL9.8An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user...
CVE-2025-11698CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit...
CVE-2025-12012CRITICAL9.2A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u...
CVE-2025-12011CRITICAL9.2A denial-of-service issue exists in  5370/5570 controllers. This vulnerability could potentially allow a remote user to ...
CVE-2025-58151CRITICAL9.4varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ...
CVE-2025-58146CRITICAL9.4There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica...
CVE-2025-27464CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27463CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-27462CRITICAL9.4[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi...
CVE-2025-53830CRITICAL9.1Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud...
CVE-2025-53827CRITICAL9.1ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi...
CVE-2025-23351CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-23350CRITICAL9NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ...
CVE-2025-15646CRITICAL9.8HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now