2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-40897HIGH8.1An access control vulnerability was discovered in the Threat Intelligence functionality due to a specific access restric...
CVE-2025-54550HIGH8.1The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xco...
CVE-2025-15470MEDIUM6.5The Eleganzo theme for WordPress is vulnerable to arbitrary directory deletion due to insufficient path validation in th...
CVE-2025-15565MEDIUM5.3The Nexi XPay plugin for WordPress is vulnerable to unauthorized modification of data due to missing authorization check...
CVE-2025-70023CRITICAL9.8An issue pertaining to CWE-843: Access of Resource Using Incompatible Type was discovered in transloadit uppy v0.25.6.
CVE-2025-68649MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyze...
CVE-2025-65136MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php v...
CVE-2025-65135CRITICAL9.8In manikandan580 School-management-system 1.0, a time-based blind SQL injection vulnerability exists in /studentms/admin...
CVE-2025-65134MEDIUM6.1In manikandan580 School-management-system 1.0, a reflected cross-site scripting (XSS) vulnerability exists in /studentms...
CVE-2025-65133CRITICAL9.8A SQL injection vulnerability exists in the School Management System (version 1.0) by manikandan580. An unauthenticated ...
CVE-2025-65132MEDIUM6.1alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which a...
CVE-2025-63939CRITICAL9.8Improper input handling in /Grocery/search_products_itname.php, in anirudhkannan Grocery Store Management System 1.0, al...
CVE-2025-61886MEDIUM5.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerabi...
CVE-2025-61848HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiA...
CVE-2025-61624MEDIUM6.5An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet For...
CVE-2025-59809MEDIUM4.3A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR P...
CVE-2025-53847HIGH8.8A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro...
CVE-2025-69993MEDIUM6.1Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This...
CVE-2025-69893MEDIUM4.6A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13...
CVE-2025-61260CRITICAL9.8A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP ...
CVE-2025-8095CRITICAL9.1The OECH1 prefix encoding is intended to obfuscate values across the OpenEdge platform.  It has been identified as crypt...
CVE-2025-7389HIGH8.2A vulnerability in the AdminServer component of OpenEdge on all supported platforms grants its authenticated users OS-le...
CVE-2025-13822MEDIUM5.3MCPHub in versions below 0.11.0 is vulnerable to authentication bypass. Some endpoints are not protected by authenticati...
CVE-2025-40745MEDIUM6.3A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V...
CVE-2025-70936MEDIUM5.4Vtiger CRM 8.4.0 contains a reflected cross-site scripting (XSS) vulnerability in the MailManager module. Improper handl...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now