2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11516 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /... |
| CVE-2025-11515 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | A security flaw has been discovered in code-projects Online Complaint Site 1.0. This issue affects some unknown processi... |
| CVE-2025-11514 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | A vulnerability was identified in code-projects Online Complaint Site 1.0. This vulnerability affects unknown code of th... |
| CVE-2025-11535 | HIGH | 8.8 | 0.1% | Oct 8, 2025 | MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privileg... |
| CVE-2025-60311 | HIGH | 8.8 | 0.4% | Oct 8, 2025 | ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php pag... |
| CVE-2025-61524 | HIGH | 7.2 | 0.6% | Oct 8, 2025 | An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and bef... |
| CVE-2025-57457 | HIGH | 8.8 | 1.1% | Oct 8, 2025 | An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject ... |
| CVE-2025-9868 | HIGH | 8.7 | 0.5% | Oct 8, 2025 | Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.1... |
| CVE-2025-11489 | HIGH | 7 | 0.2% | Oct 8, 2025 | A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects ... |
| CVE-2025-11488 | HIGH | 7.3 | 1.7% | Oct 8, 2025 | A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Execu... |
| CVE-2025-9970 | HIGH | 7.4 | 0.1% | Oct 8, 2025 | Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1.... |
| CVE-2025-53967 | HIGH | 8 | 7.4% | Oct 8, 2025 | Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system ... |
| CVE-2025-11478 | HIGH | 8.8 | 0.3% | Oct 8, 2025 | A weakness has been identified in SourceCodester Farm Management System 1.0. This issue affects some unknown processing ... |
| CVE-2025-11470 | HIGH | 7.2 | 0.4% | Oct 8, 2025 | A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted e... |
| CVE-2025-11444 | HIGH | 8.8 | 1.0% | Oct 8, 2025 | A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function set... |
| CVE-2025-11436 | HIGH | 8.8 | 0.3% | Oct 8, 2025 | A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the... |
| CVE-2025-10635 | HIGH | 7.7 | 0.2% | Oct 8, 2025 | The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statem... |
| CVE-2025-11204 | HIGH | 7.2 | 0.4% | Oct 8, 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2025-10494 | HIGH | 8.1 | 0.4% | Oct 8, 2025 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion d... |
| CVE-2025-11426 | HIGH | 8.8 | 0.3% | Oct 8, 2025 | A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerabil... |
| CVE-2025-61787 | HIGH | 8.1 | 2.1% | Oct 8, 2025 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command ... |
| CVE-2025-48981 | HIGH | 8.6 | 0.1% | Oct 8, 2025 | An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet t... |
| CVE-2025-11417 | HIGH | 8.8 | 0.3% | Oct 8, 2025 | A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unk... |
| CVE-2025-11410 | HIGH | 8.8 | 0.3% | Oct 7, 2025 | A flaw has been found in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the... |
| CVE-2025-62186 | HIGH | 7.8 | 0.1% | Oct 7, 2025 | Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now