2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11609HIGH8.1A flaw has been found in code-projects Hospital Management System 1.0. Affected is the function session of the component...
CVE-2025-11607HIGH8.8A weakness has been identified in harry0703 MoneyPrinterTurbo up to 1.2.6. The impacted element is the function upload_m...
CVE-2025-11605HIGH8.8A vulnerability was identified in code-projects Client Details System 1.0. Impacted is an unknown function of the file /...
CVE-2025-11603HIGH8.8A vulnerability was found in code-projects Simple Food Ordering System 1.0. This vulnerability affects unknown code of t...
CVE-2025-11600HIGH8.8A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Affected is an unknown func...
CVE-2025-8593HIGH8.8The GSheetConnector For Gravity Forms plugin for WordPress is vulnerable to authorization bypass in versions less than, ...
CVE-2025-11593HIGH8.8A flaw has been found in CodeAstro Gym Management System 1.0. This vulnerability affects unknown code of the file /admin...
CVE-2025-11592HIGH8.8A vulnerability was detected in CodeAstro Gym Management System 1.0. This affects an unknown part of the file /admin/edi...
CVE-2025-11591HIGH8.8A security vulnerability has been detected in CodeAstro Gym Management System 1.0. Affected by this issue is some unknow...
CVE-2025-31718HIGH7.5In modem, there is a possible system crash due to improper input validation. This could lead to remote escalation of pri...
CVE-2025-31717HIGH7.5In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2025-11590HIGH8.8A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown func...
CVE-2025-8093HIGH8.8Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Authenticator Login allows Authenticati...
CVE-2025-62162HIGH7.5cel-rust is a Common Expression Language interpreter written in Rust. Starting in version 0.10.0 and prior to version 0....
CVE-2025-62159HIGH8.7External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete...
CVE-2025-11589HIGH8.8A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ...
CVE-2025-11588HIGH8.8A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /cus...
CVE-2025-61930HIGH8.8Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Requ...
CVE-2025-61927HIGH7.2Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower ...
CVE-2025-61921HIGH7.5Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a deni...
CVE-2025-61920HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implem...
CVE-2025-61919HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the...
CVE-2025-55903HIGH8.3A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To...
CVE-2025-60880HIGH8.3An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an a...
CVE-2025-11581HIGH7.5A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now