2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-13080MEDIUM5.3Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This i...
CVE-2025-12761LOW3.5Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple mult...
CVE-2025-12760MEDIUM5.4Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.T...
CVE-2025-9977MEDIUM5.3Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not saniti...
CVE-2025-64996MEDIUM4.4In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates worl...
CVE-2025-63800HIGH7.5The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty s...
CVE-2025-63604MEDIUM6.5A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code executi...
CVE-2025-63603MEDIUM6.5A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) ...
CVE-2025-63602HIGH7.3A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MS...
CVE-2025-63408HIGH7.8Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacke...
CVE-2025-58122MEDIUM5.4Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notifi...
CVE-2025-58121MEDIUM5.4Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4....
CVE-2025-55074LOW3.5Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which ...
CVE-2025-12383HIGH7.4In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such...
CVE-2025-9312CRITICAL9.8A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP...
CVE-2025-8084MEDIUM6.8The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3....
CVE-2025-63892MEDIUM6.8A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_c...
CVE-2025-63883MEDIUM5.4A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client...
CVE-2025-59117MEDIUM4.8Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu...
CVE-2025-59116MEDIUM5.3Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow ...
CVE-2025-59115MEDIUM5.4Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation...
CVE-2025-59114MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft spec...
CVE-2025-59113HIGH7.5Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt co...
CVE-2025-59112MEDIUM6.5Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft specia...
CVE-2025-59111MEDIUM6.5Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now