2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11516HIGH8.8A weakness has been identified in code-projects Online Complaint Site 1.0. Impacted is an unknown function of the file /...
CVE-2025-11515HIGH8.8A security flaw has been discovered in code-projects Online Complaint Site 1.0. This issue affects some unknown processi...
CVE-2025-11514HIGH8.8A vulnerability was identified in code-projects Online Complaint Site 1.0. This vulnerability affects unknown code of th...
CVE-2025-11535HIGH8.8MongoDB Connector for BI installation via MSI on Windows leaves ACLs unset on custom install directories allows Privileg...
CVE-2025-60311HIGH8.8ProjectWorlds Gym Management System1.0 is vulnerable to SQL Injection via the "id" parameter in the profile/edit.php pag...
CVE-2025-61524HIGH7.2An issue in the permission verification module and organization/application editing interface in Casdoor v2.26.0 and bef...
CVE-2025-57457HIGH8.8An OS Command Injection vulnerability in the Admin panel in Curo UC300 5.42.1.7.1.63R1 allows local attackers to inject ...
CVE-2025-9868HIGH8.7Server-Side Request Forgery (SSRF) in the Remote Browser Plugin in Sonatype Nexus Repository 2.x up to and including 2.1...
CVE-2025-11489HIGH7A security vulnerability has been detected in wonderwhy-er DesktopCommanderMCP up to 0.2.13. This vulnerability affects ...
CVE-2025-11488HIGH7.3A weakness has been identified in D-Link DIR-852 up to 20251002. This affects an unknown part of the file /HNAP1/. Execu...
CVE-2025-9970HIGH7.4Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1....
CVE-2025-53967HIGH8Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system ...
CVE-2025-11478HIGH8.8A weakness has been identified in SourceCodester Farm Management System 1.0. This issue affects some unknown processing ...
CVE-2025-11470HIGH7.2A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted e...
CVE-2025-11444HIGH8.8A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function set...
CVE-2025-11436HIGH8.8A vulnerability was detected in JhumanJ OpnForm up to 1.9.3. Affected by this issue is some unknown functionality of the...
CVE-2025-10635HIGH7.7The Find Me On WordPress plugin through 2.0.9.1 does not sanitize and escape a parameter before using it in a SQL statem...
CVE-2025-11204HIGH7.2The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu...
CVE-2025-10494HIGH8.1The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to arbitrary file deletion d...
CVE-2025-11426HIGH8.8A security flaw has been discovered in projectworlds Advanced Library Management System 1.0. Affected by this vulnerabil...
CVE-2025-61787HIGH8.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command ...
CVE-2025-48981HIGH8.6An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet t...
CVE-2025-11417HIGH8.8A weakness has been identified in Campcodes Advanced Online Voting Management System 1.0. This vulnerability affects unk...
CVE-2025-11410HIGH8.8A flaw has been found in Campcodes Advanced Online Voting Management System 1.0. This affects an unknown function of the...
CVE-2025-62186HIGH7.8Ankitects Anki before 25.02.5 allows a crafted shared deck on Windows to execute arbitrary commands when playing audio b...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now