2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65135CRITICAL9.8In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin...
CVE-2025-65134MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms...
CVE-2025-65133CRITICAL9.8A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ...
CVE-2025-65132MEDIUM6.1alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a...
CVE-2025-63939CRITICAL9.8Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al...
CVE-2025-61886MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-61848HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-61624MEDIUM6.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For...
CVE-2025-59809MEDIUM4.3A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P...
CVE-2025-53847HIGH8.8A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro...
CVE-2025-69993MEDIUM6.1Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This...
CVE-2025-69893MEDIUM4.6A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13...
CVE-2025-61260CRITICAL9.8A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ...
CVE-2025-8095CRITICAL9.1The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as crypt...
CVE-2025-7389HIGH8.2A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le...
CVE-2025-13822MEDIUM5.3MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati...
CVE-2025-40745MEDIUM6.3A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V...
CVE-2025-70936MEDIUM5.4Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl...
CVE-2025-51414HIGH8.8In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile ...
CVE-2025-3756HIGH7.1A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li...
CVE-2025-69627HIGH8.4Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript...
CVE-2025-69624HIGH7.5Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio...
CVE-2025-66769HIGH7.5A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v...
CVE-2025-63743MEDIUM5.4Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a...
CVE-2025-31991CRITICAL9.8Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now