2025 CVE Vulnerabilities

45,203 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58410HIGH7.5Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to m...
CVE-2025-13319HIGH8.8An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with val...
CVE-2025-13291CRITICAL9.8A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufac...
CVE-2025-13290HIGH8.8A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown ...
CVE-2025-13193MEDIUM5.5A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, ma...
CVE-2025-65083LOW3.2GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be prob...
CVE-2025-64046MEDIUM6.1OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php.
CVE-2025-63916HIGH8.1MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The applicati...
CVE-2025-63748HIGH8.8QaTraq 6.9.2 allows authenticated users to upload arbitrary files via the "Add Attachment" feature in the "Test Script" ...
CVE-2025-63747CRITICAL9.8QaTraq 6.9.2 ships with administrative account credentials which are enabled in default installations and permit immedia...
CVE-2025-63708MEDIUM6.1Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows re...
CVE-2025-13289HIGH8.8A vulnerability was detected in 1000projects Design & Development of Student Database Management System 1.0. Affected is...
CVE-2025-13288HIGH8.8A security vulnerability has been detected in Tenda CH22 1.0.0.1. This impacts the function fromPptpUserSetting of the f...
CVE-2025-4321HIGH7.1In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP pack...
CVE-2025-13310Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-13287HIGH8.8A weakness has been identified in itsourcecode Online Voting System 1.0. This affects an unknown function of the file /i...
CVE-2025-13286HIGH8.8A security flaw has been discovered in itsourcecode Online Voting System 1.0. The impacted element is an unknown functio...
CVE-2025-13285CRITICAL9.8A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of ...
CVE-2025-13280CRITICAL9.8A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of ...
CVE-2025-13279HIGH8.8A vulnerability was found in code-projects Nero Social Networking Site 1.0. The affected element is an unknown function ...
CVE-2025-13278HIGH8.8A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Impacted is an unknown function ...
CVE-2025-40936HIGH7.8A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Fema...
CVE-2025-40834MEDIUM6.8A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not prope...
CVE-2025-13277CRITICAL9.8A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of th...
CVE-2025-11681MEDIUM6.5Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now