2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69948 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in /admin/delete_group.php?id=1. |
| CVE-2025-69946 | CRITICAL | 9.8 | 0.2% | Jul 31, 2026 | SourceCodester Modern Loan Management System 1.0 is vulnerable to SQL Injection in ajaxData.php via the parameters distr... |
| CVE-2025-62347 | MEDIUM | 4.3 | — | Jul 31, 2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and... |
| CVE-2025-67651 | MEDIUM | 6.9 | — | Jul 31, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF ... |
| CVE-2025-67650 | HIGH | 8.6 | — | Jul 31, 2026 | An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralizatio... |
| CVE-2025-67649 | CRITICAL | 9.3 | — | Jul 31, 2026 | A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input ... |
| CVE-2025-69947 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. |
| CVE-2025-69941 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. |
| CVE-2025-69938 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. |
| CVE-2025-69937 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Paramete... |
| CVE-2025-69936 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. |
| CVE-2025-69935 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via th... |
| CVE-2025-69934 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. |
| CVE-2025-69933 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. |
| CVE-2025-69931 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. |
| CVE-2025-69930 | CRITICAL | 9.8 | 0.1% | Jul 30, 2026 | CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. |
| CVE-2025-65342 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. |
| CVE-2025-65341 | MEDIUM | 6.1 | 0.1% | Jul 30, 2026 | Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. |
| CVE-2025-65336 | CRITICAL | 9.8 | 0.2% | Jul 30, 2026 | Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. |
| CVE-2025-51684 | MEDIUM | 6.1 | 0.2% | Jul 30, 2026 | CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data ... |
| CVE-2025-36374 | MEDIUM | 5.5 | — | Jul 30, 2026 | IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile... |
| CVE-2025-0152 | MEDIUM | 6.1 | — | Jul 30, 2026 | IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1... |
| CVE-2025-36431 | MEDIUM | 5.4 | — | Jul 30, 2026 | IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera... |
| CVE-2025-36298 | MEDIUM | 5.4 | 0.2% | Jul 30, 2026 | IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0... |
| CVE-2025-69949 | HIGH | 7.3 | — | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in check_availability.php via the parameters em... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now