2025 CVE Vulnerabilities

45,184 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65657MEDIUM6.5FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1...
CVE-2025-65380MEDIUM6.5PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username...
CVE-2025-64778HIGH7.8NMIS/BioDose software V22.02 and previous versions contain executable binaries with plain text hard-coded passwords. The...
CVE-2025-64642HIGH7.8NMIS/BioDose V22.02 and previous versions' installation directory paths by default have insecure file permissions, which...
CVE-2025-64298HIGH7.5NMIS/BioDose V22.02 and previous version installations where the embedded Microsoft SQLServer Express is used are expose...
CVE-2025-62575HIGH8.8NMIS/BioDose V22.02 and previous versions rely on a Microsoft SQL Server database. The SQL user account 'nmdbuser' and o...
CVE-2025-61940HIGH8.8NMIS/BioDose V22.02 and previous versions rely on a common SQL Server user account to access data in the database. User ...
CVE-2025-65877HIGH7.5Lvzhou CMS before commit c4ea0eb9cab5f6739b2c87e77d9ef304017ed615 (2025-09-22) is vulnerable to SQL injection via the 't...
CVE-2025-65379MEDIUM6.5PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,...
CVE-2025-13658CRITICAL9.3A vulnerability in Longwatch devices allows unauthenticated HTTP GET requests to execute arbitrary code via an exposed e...
CVE-2025-13542CRITICAL9.8The DesignThemes LMS plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1....
CVE-2025-13510CRITICAL9.3The Iskra iHUB and iHUB Lite smart metering gateway exposes its web management interface without requiring authenticatio...
CVE-2025-66468MEDIUM6.1The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior ...
CVE-2025-66460MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66459MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66458MEDIUM6.1Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac...
CVE-2025-66454MEDIUM6.5Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a har...
CVE-2025-66416HIGH8.1The MCP Python SDK, called `mcp` on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to versi...
CVE-2025-66414HIGH8.1MCP TypeScript SDK is the official TypeScript SDK for Model Context Protocol servers and clients. Prior to 1.24.0, The M...
CVE-2025-66409CRITICAL9.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earli...
CVE-2025-65896CRITICAL9.8SQL injection vulnerability in long2ice assyncmy thru 0.2.10 allows attackers to execute arbitrary SQL commands via craf...
CVE-2025-61729HIGH7.5Within HostnameError.Error(), when constructing an error string, there is no limit to the number of hosts that will be p...
CVE-2025-60736CRITICAL9.8code-projects Online Medicine Guide 1.0 is vulnerable to SQL Injection in /login.php via the upass parameter.
CVE-2025-57850MEDIUM6.4A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p...
CVE-2025-34352HIGH8.5JumpCloud Remote Assist for Windows versions prior to 0.317.0 include an uninstaller that is invoked by the JumpCloud Wi...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now