2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65135 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin... |
| CVE-2025-65134 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms... |
| CVE-2025-65133 | CRITICAL | 9.8 | 0.5% | Apr 14, 2026 | A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ... |
| CVE-2025-65132 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a... |
| CVE-2025-63939 | CRITICAL | 9.8 | 0.3% | Apr 14, 2026 | Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al... |
| CVE-2025-61886 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi... |
| CVE-2025-61848 | HIGH | 7.2 | 0.5% | Apr 14, 2026 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA... |
| CVE-2025-61624 | MEDIUM | 6.5 | 0.5% | Apr 14, 2026 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For... |
| CVE-2025-59809 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P... |
| CVE-2025-53847 | HIGH | 8.8 | 0.3% | Apr 14, 2026 | A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro... |
| CVE-2025-69993 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This... |
| CVE-2025-69893 | MEDIUM | 4.6 | 0.2% | Apr 14, 2026 | A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13... |
| CVE-2025-61260 | CRITICAL | 9.8 | 7.1% | Apr 14, 2026 | A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ... |
| CVE-2025-8095 | CRITICAL | 9.1 | 0.2% | Apr 14, 2026 | The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform. It has been identified as crypt... |
| CVE-2025-7389 | HIGH | 8.2 | 0.3% | Apr 14, 2026 | A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le... |
| CVE-2025-13822 | MEDIUM | 5.3 | 0.4% | Apr 14, 2026 | MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati... |
| CVE-2025-40745 | MEDIUM | 6.3 | 0.1% | Apr 14, 2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V... |
| CVE-2025-70936 | MEDIUM | 5.4 | 0.1% | Apr 13, 2026 | Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl... |
| CVE-2025-51414 | HIGH | 8.8 | 0.3% | Apr 13, 2026 | In Phpgurukul Online Course Registration v3.1, an arbitrary file upload vulnerability was discovered within the profile ... |
| CVE-2025-3756 | HIGH | 7.1 | 0.2% | Apr 13, 2026 | A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions li... |
| CVE-2025-69627 | HIGH | 8.4 | 0.2% | Apr 13, 2026 | Nitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript... |
| CVE-2025-69624 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | Nitro PDF Pro before 14.43 for Windows contains a NULL pointer dereference vulnerability in the JavaScript implementatio... |
| CVE-2025-66769 | HIGH | 7.5 | 0.4% | Apr 13, 2026 | A NULL pointer dereference in Nitro PDF Pro for Windows v14.41.1.4 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2025-63743 | MEDIUM | 5.4 | 0.3% | Apr 13, 2026 | Cross-Site Scripting vulnerability in the Snipe-IT web-based asset management system v8.3.0 to up and including v8.3.1 a... |
| CVE-2025-31991 | CRITICAL | 9.8 | 0.2% | Apr 13, 2026 | Rate Limiting for attempting a user login is not being properly enforced, making HCL DevOps Velocity susceptible to brut... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now