2025 CVE Vulnerabilities

45,325 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11588HIGH8.8A vulnerability was identified in CodeAstro Gym Management System 1.0. This impacts an unknown function of the file /cus...
CVE-2025-61930HIGH8.8Emlog is an open source website building system. Emlog Pro versions 2.5.19 and earlier are vulnerable to Cross‑Site Requ...
CVE-2025-61927HIGH7.2Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower ...
CVE-2025-61921HIGH7.5Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a deni...
CVE-2025-61920HIGH7.5Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to version 1.6.5, Authlib’s JOSE implem...
CVE-2025-61919HIGH7.5Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, `Rack::Request#POST` reads the...
CVE-2025-55903HIGH8.3A HTML injection vulnerability exists in Perfex CRM v3.3.1. The application fails to sanitize user input in the "Bill To...
CVE-2025-60880HIGH8.3An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an a...
CVE-2025-11581HIGH7.5A security vulnerability has been detected in PowerJob up to 5.1.2. This vulnerability affects unknown code of the file ...
CVE-2025-23309HIGH8.2NVIDIA Display Driver contains a vulnerability where an uncontrolled DLL loading path might lead to arbitrary denial of ...
CVE-2025-23282HIGH7NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to use a race condition to esca...
CVE-2025-23280HIGH7NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex...
CVE-2025-61689HIGH8.7HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl...
CVE-2025-60305HIGH8.8SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a...
CVE-2025-59530HIGH7.5quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving ...
CVE-2025-48043HIGH8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This issue affects ash: from 0.1...
CVE-2025-60869HIGH7.3Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fie...
CVE-2025-60378HIGH8.1Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into in...
CVE-2025-61864HIGH8.4A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially craft...
CVE-2025-61863HIGH8.4An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening sp...
CVE-2025-61862HIGH8.4An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening sp...
CVE-2025-61861HIGH8.4An out-of-bounds read vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially ...
CVE-2025-61860HIGH8.4An out-of-bounds read vulnerability exists in VS6MemInIF!set_temp_type_default of V-SFT v6.2.7.0 and earlier. Opening sp...
CVE-2025-61859HIGH8.4An out-of-bounds write vulnerability exists in VS6ComFile!CItemDraw::is_motion_tween of V-SFT v6.2.7.0 and earlier. Open...
CVE-2025-61858HIGH8.4An out-of-bounds write vulnerability exists in VS6ComFile!set_AnimationItem of V-SFT v6.2.7.0 and earlier. Opening speci...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now