2025 CVE Vulnerabilities

45,158 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-47696HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-9690HIGH8.8A flaw has been found in SourceCodester Advanced School Management System 1.0. This affects an unknown function of the f...
CVE-2025-9689HIGH8.8A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown...
CVE-2025-9687HIGH8.8A weakness has been identified in Portabilis i-Educar up to 2.10. Impacted is an unknown function of the file /module/Hi...
CVE-2025-9686HIGH8.8A security flaw has been discovered in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the...
CVE-2025-9685HIGH8.8A vulnerability was identified in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /m...
CVE-2025-9684HIGH8.8A vulnerability was determined in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Formu...
CVE-2025-38677HIGH7.1In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to avoid out-of-boundary access in dnode ...
CVE-2025-34165HIGH8.8A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, una...
CVE-2025-58159HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was i...
CVE-2025-58157HIGH7.5gnark is a zero-knowledge proof system framework. In version 0.12.0, there is a potential denial of service vulnerabilit...
CVE-2025-57822HIGH8.2Next.js is a React framework for building full-stack web applications. Prior to versions 14.2.32 and 15.4.7, when next()...
CVE-2025-56577HIGH8.4An issue in Evope Core v.1.1.3.20 allows a local attacker to obtain sensitive information via the use of hard coded cryp...
CVE-2025-9667HIGH8.8A vulnerability was detected in code-projects Simple Grading System 1.0. This affects an unknown part of the file /delet...
CVE-2025-9666HIGH8.8A security vulnerability has been detected in code-projects Simple Grading System 1.0. Affected by this issue is some un...
CVE-2025-9665HIGH8.8A weakness has been identified in code-projects Simple Grading System 1.0. Affected by this vulnerability is an unknown ...
CVE-2025-9377HIGH7.2The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link Archer C7...
CVE-2025-58158HIGH8.8Harness Open Source is an end-to-end developer platform with Source Control Management, CI/CD Pipelines, Hosted Develope...
CVE-2025-52861HIGH7A path traversal vulnerability has been reported to affect VioStor. If a remote attacker gains an administrator account,...
CVE-2025-44015HIGH8.4A command injection vulnerability has been reported to affect HybridDesk Station. If an attacker gains local network acc...
CVE-2025-30278HIGH8.8An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a...
CVE-2025-30277HIGH8.8An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a...
CVE-2025-30273HIGH8.1An out-of-bounds write vulnerability has been reported to affect several QNAP operating system versions. If a remote att...
CVE-2025-30264HIGH8.8A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2025-29894HIGH8.8An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now