2025 CVE Vulnerabilities

45,319 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-71403HIGH7.1better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute ...
CVE-2025-67650HIGH8.6An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio...
CVE-2025-69949HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em...
CVE-2025-69945HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1.
CVE-2025-69944HIGH7.3kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie...
CVE-2025-67408HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ...
CVE-2025-67407HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters...
CVE-2025-67406HIGH7.3https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu...
CVE-2025-67405HIGH7.3Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param...
CVE-2025-60931HIGH7.5An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33...
CVE-2025-63913HIGH7.5An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu...
CVE-2025-59172HIGH8.5Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln...
CVE-2025-15662HIGH8.6The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl...
CVE-2025-71408HIGH8.5NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m...
CVE-2025-60835HIGH7.8An issue in the unrar.dll component of IZArc v4.6 allows attackers to execute a path traversal.
CVE-2025-50330HIGH8.8An issue in ZipGenius Team ZipGenius v.6.3.2.3116 and before allows a remote attacker to escalate privileges and execute...
CVE-2025-50327HIGH8.8An issue in Franco Corbelli ZPAQFRANZ v.61.3 and before allows a remote attacker to escalate privileges and execute arbi...
CVE-2025-50324HIGH8.8An issue in Milos Paripovic OneCommander v.3.96.0.0 allows a remote attacker to execute arbitrary code via the OneComman...
CVE-2025-44090HIGH8.8An issue in OhSoft CoffeeZip v4.8.0.0 allows attackers to execute arbitrary code via downloading and executing a crafted...
CVE-2025-44089HIGH8.8An issue in NCH Software ExpressZip v11.29 allows attackers to execute arbitrary code via downloading and executing a cr...
CVE-2025-71398HIGH7.6SurrealDB before 2.2.2 fails to validate HTTP redirects in http functions, allowing authenticated users to bypass deny-n...
CVE-2025-71392HIGH8SurrealDB before 2.0.5, 2.1.x before 2.1.5, and 2.2.x before 2.2.2 fails to properly escape table and field names in the...
CVE-2025-71390HIGH8.8SurrealDB before 2.2.6, 2.3.6, and 2.1.8 (and 3.0.0-alpha.7 and earlier) fails to validate DNS-resolved hostnames agains...
CVE-2025-51678HIGH7.5An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to une...
CVE-2025-60357HIGH8.1AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEv...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now