2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-25196 | CRITICAL | 9.8 | 0.4% | Feb 19, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2025-25467 | CRITICAL | 9.8 | 0.6% | Feb 18, 2025 | Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary... |
| CVE-2025-26617 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26613 | CRITICAL | 9.8 | 2.6% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. An OS Command Injection ... |
| CVE-2025-26612 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26611 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26610 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26609 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26608 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26607 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26606 | CRITICAL | 9.8 | 0.5% | Feb 18, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab... |
| CVE-2025-26623 | CRITICAL | 9.8 | 0.8% | Feb 18, 2025 | Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metada... |
| CVE-2025-22654 | CRITICAL | 10 | 0.9% | Feb 18, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in kodeshpa Simplified simplified allows Using Malicious F... |
| CVE-2025-24895 | CRITICAL | 9.1 | 0.6% | Feb 18, 2025 | CIE.AspNetCore.Authentication is an AspNetCore Remote Authenticator for CIE 3.0. Authentication using Spid and CIE is ba... |
| CVE-2025-24894 | CRITICAL | 9.1 | 0.6% | Feb 18, 2025 | SPID.AspNetCore.Authentication is an AspNetCore Remote Authenticator for SPID. Authentication using Spid and CIE is base... |
| CVE-2025-1023 | CRITICAL | 9.8 | 2.2% | Feb 18, 2025 | A vulnerability exists in ChurchCRM 5.13.0 and prior that allows an attacker to execute arbitrary SQL queries by exploit... |
| CVE-2025-25222 | CRITICAL | 9.8 | 0.4% | Feb 18, 2025 | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v... |
| CVE-2025-25221 | CRITICAL | 9.8 | 0.4% | Feb 18, 2025 | The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains an SQL injection v... |
| CVE-2025-1380 | CRITICAL | 9.8 | 0.5% | Feb 17, 2025 | A vulnerability was found in Codezips Gym Management System 1.0 and classified as critical. Affected by this issue is so... |
| CVE-2025-1379 | CRITICAL | 9.8 | 0.5% | Feb 17, 2025 | A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. A... |
| CVE-2025-1387 | CRITICAL | 9.8 | 0.5% | Feb 17, 2025 | Orca HCM from LEARNING DIGITAL has an Improper Authentication vulnerability, allowing unauthenticated remote attackers t... |
| CVE-2025-22290 | CRITICAL | 9.3 | 0.3% | Feb 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology ... |
| CVE-2025-22289 | CRITICAL | 9.8 | 0.4% | Feb 16, 2025 | Missing Authorization vulnerability in enituretechnology LTL Freight Quotes – Unishippers Edition ltl-freight-quotes-uni... |
| CVE-2025-1355 | CRITICAL | 9.8 | 0.8% | Feb 16, 2025 | A vulnerability was found in needyamin Library Card System 1.0. It has been declared as critical. Affected by this vulne... |
| CVE-2025-26793 | CRITICAL | 9.3 | 2.3% | Feb 15, 2025 | The Web GUI configuration panel of Hirsch (formerly Identiv and Viscount) Enterphone MESH through 2024 ships with defaul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now