2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-67650 | HIGH | 8.6 | — | Jul 31, 2026 | An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio... |
| CVE-2025-69949 | HIGH | 7.3 | — | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em... |
| CVE-2025-69945 | HIGH | 7.3 | — | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. |
| CVE-2025-69944 | HIGH | 7.3 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie... |
| CVE-2025-67408 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ... |
| CVE-2025-67407 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters... |
| CVE-2025-67406 | HIGH | 7.3 | — | Jul 29, 2026 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu... |
| CVE-2025-67405 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param... |
| CVE-2025-60931 | HIGH | 7.5 | — | Jul 29, 2026 | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33... |
| CVE-2025-63913 | HIGH | 7.5 | 0.1% | Jul 27, 2026 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu... |
| CVE-2025-59172 | HIGH | 8.5 | 0.2% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln... |
| CVE-2025-15662 | HIGH | 8.6 | — | Jul 27, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl... |
| CVE-2025-71408 | HIGH | 8.5 | 0.2% | Jul 24, 2026 | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m... |
| CVE-2025-60835 | HIGH | 7.8 | 0.2% | Jul 22, 2026 | An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal. |
| CVE-2025-50330 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute... |
| CVE-2025-50327 | HIGH | 8.8 | 0.3% | Jul 22, 2026 | An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi... |
| CVE-2025-50324 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman... |
| CVE-2025-44090 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted... |
| CVE-2025-44089 | HIGH | 8.8 | 0.2% | Jul 22, 2026 | An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr... |
| CVE-2025-71397 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi... |
| CVE-2025-71395 | HIGH | 7.1 | 0.2% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ... |
| CVE-2025-71391 | HIGH | 7.1 | 0.3% | Jul 18, 2026 | SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ... |
| CVE-2025-51678 | HIGH | 7.5 | 0.4% | Jul 17, 2026 | An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une... |
| CVE-2025-60357 | HIGH | 8.1 | 0.3% | Jul 17, 2026 | AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv... |
| CVE-2025-45868 | HIGH | 8.8 | 0.2% | Jul 16, 2026 | LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now