2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11609 | HIGH | 8.1 | 0.5% | Oct 11, 2025 | A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component... |
| CVE-2025-11607 | HIGH | 8.8 | 0.4% | Oct 11, 2025 | A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_m... |
| CVE-2025-11605 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /... |
| CVE-2025-11603 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of t... |
| CVE-2025-11600 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown func... |
| CVE-2025-8593 | HIGH | 8.8 | 0.4% | Oct 11, 2025 | The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, ... |
| CVE-2025-11593 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin... |
| CVE-2025-11592 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edi... |
| CVE-2025-11591 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknow... |
| CVE-2025-31718 | HIGH | 7.5 | 0.6% | Oct 11, 2025 | In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of pri... |
| CVE-2025-31717 | HIGH | 7.5 | 0.6% | Oct 11, 2025 | In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service... |
| CVE-2025-11590 | HIGH | 8.8 | 0.3% | Oct 11, 2025 | A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown func... |
| CVE-2025-8093 | HIGH | 8.8 | 0.3% | Oct 10, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati... |
| CVE-2025-62162 | HIGH | 7.5 | 0.3% | Oct 10, 2025 | cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0.... |
| CVE-2025-62159 | HIGH | 8.7 | 0.3% | Oct 10, 2025 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2025-11589 | HIGH | 8.8 | 0.3% | Oct 10, 2025 | A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ... |
| CVE-2025-11588 | HIGH | 8.8 | 0.3% | Oct 10, 2025 | A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /cus... |
| CVE-2025-61930 | HIGH | 8.8 | 0.2% | Oct 10, 2025 | Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Requ... |
| CVE-2025-61927 | HIGH | 7.2 | 0.6% | Oct 10, 2025 | Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower ... |
| CVE-2025-61921 | HIGH | 7.5 | 0.4% | Oct 10, 2025 | Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a deni... |
| CVE-2025-61920 | HIGH | 7.5 | 0.6% | Oct 10, 2025 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implem... |
| CVE-2025-61919 | HIGH | 7.5 | 0.6% | Oct 10, 2025 | Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the... |
| CVE-2025-55903 | HIGH | 8.3 | 0.3% | Oct 10, 2025 | A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To... |
| CVE-2025-60880 | HIGH | 8.3 | 0.4% | Oct 10, 2025 | An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an a... |
| CVE-2025-11581 | HIGH | 7.5 | 0.4% | Oct 10, 2025 | A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now