2025 CVE Vulnerabilities

45,137 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-67650HIGH8.6An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio...
CVE-2025-69949HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em...
CVE-2025-69945HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie...
CVE-2025-67408HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ...
CVE-2025-67407HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters...
CVE-2025-67406HIGH7.3https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu...
CVE-2025-67405HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param...
CVE-2025-60931HIGH7.5An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33...
CVE-2025-63913HIGH7.5An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu...
CVE-2025-59172HIGH8.5Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln...
CVE-2025-15662HIGH8.6The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl...
CVE-2025-71408HIGH8.5NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m...
CVE-2025-60835HIGH7.8An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330HIGH8.8An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute...
CVE-2025-50327HIGH8.8An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi...
CVE-2025-50324HIGH8.8An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman...
CVE-2025-44090HIGH8.8An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted...
CVE-2025-44089HIGH8.8An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr...
CVE-2025-71397HIGH7.1SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 allows authenticated users with OWNER or EDITOR permi...
CVE-2025-71395HIGH7.1SurrealDB versions before 2.2.2 contain a memory exhaustion vulnerability in the string::replace function that fails to ...
CVE-2025-71391HIGH7.1SurrealDB versions before 2.2.2 contain an uncaught exception vulnerability in the net module that allows authenticated ...
CVE-2025-51678HIGH7.5An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une...
CVE-2025-60357HIGH8.1AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv...
CVE-2025-45868HIGH8.8LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allo...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now