2025 CVE Vulnerabilities

45,146 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-11078HIGH8.8A vulnerability was identified in itsourcecode Open Source Job Portal 1.0. Affected by this vulnerability is an unknown ...
CVE-2025-11071HIGH7.2A security vulnerability has been detected in SeaCMS 13.3.20250820. Impacted is an unknown function of the file /admin_c...
CVE-2025-8014HIGH7.5Denial of Service issue in GraphQL endpoints in Gitlab EE/CE affecting all versions from 11.10 prior to 18.2.7, 18.3 pri...
CVE-2025-7647HIGH7.3The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a ...
CVE-2025-11054HIGH8.8A security vulnerability has been detected in itsourcecode Open Source Job Portal 1.0. This impacts an unknown function ...
CVE-2025-9816HIGH7.2The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cros...
CVE-2025-3193HIGH7.5Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in t...
CVE-2025-11050HIGH8.8A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E...
CVE-2025-10954HIGH7.5Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic ...
CVE-2025-11049HIGH8.8A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of ...
CVE-2025-59945HIGH8.1SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated ...
CVE-2025-59939HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks...
CVE-2025-59932HIGH8.2Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previo...
CVE-2025-59845HIGH8.2Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Pr...
CVE-2025-11048HIGH8.8A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno...
CVE-2025-11047HIGH8.8A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap...
CVE-2025-11045HIGH7.3A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function ...
CVE-2025-10657HIGH8.7In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/ha...
CVE-2025-11041HIGH8.8A vulnerability has been found in itsourcecode Open Source Job Portal 1.0. Affected by this issue is some unknown functi...
CVE-2025-11038HIGH8.8A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of t...
CVE-2025-56383HIGH8.4Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. N...
CVE-2025-55847HIGH8.8Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerab...
CVE-2025-45994HIGH7.5An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a...
CVE-2025-59844HIGH7.7SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command ...
CVE-2025-55848HIGH8.8An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interfa...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now