2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69942 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. |
| CVE-2025-67404 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters ... |
| CVE-2025-67403 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete... |
| CVE-2025-65340 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. |
| CVE-2025-10656 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Au... |
| CVE-2025-50455 | CRITICAL | 9.1 | 0.6% | Jul 27, 2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp... |
| CVE-2025-71389 | CRITICAL | 10 | 0.9% | Jul 23, 2026 | Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a versio... |
| CVE-2025-50329 | CRITICAL | 9.8 | 0.3% | Jul 22, 2026 | An issue in ConeXware, Inc Power Archiver v.22.00.11 and before allows a remote attacker to escalate privileges and exec... |
| CVE-2025-66390 | CRITICAL | 9.8 | 0.3% | Jul 21, 2026 | In Microsoft Azure API Management through 2025-10-17, when self-service signup (username/password Basic Authentication) ... |
| CVE-2025-71392 | CRITICAL | 9.4 | 0.2% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the... |
| CVE-2025-51677 | CRITICAL | 9.1 | 0.4% | Jul 17, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or12... |
| CVE-2025-65720 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user... |
| CVE-2025-11698 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers boot firmware lower than version 1.072. This vulnerabilit... |
| CVE-2025-12012 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious u... |
| CVE-2025-12011 | CRITICAL | 9.2 | — | Jul 14, 2026 | A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to ... |
| CVE-2025-58151 | CRITICAL | 9.4 | — | Jul 9, 2026 | varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF ... |
| CVE-2025-58146 | CRITICAL | 9.4 | — | Jul 9, 2026 | There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notifica... |
| CVE-2025-27464 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27463 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-27462 | CRITICAL | 9.4 | — | Jul 9, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2025-53830 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud... |
| CVE-2025-53827 | CRITICAL | 9.1 | 0.3% | Jul 6, 2026 | ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classi... |
| CVE-2025-23351 | CRITICAL | 9 | — | Jul 1, 2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ... |
| CVE-2025-23350 | CRITICAL | 9 | — | Jul 1, 2026 | NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function ... |
| CVE-2025-15646 | CRITICAL | 9.8 | 0.7% | Jul 1, 2026 | HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element w... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now