2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12308CRITICAL9.8A security flaw has been discovered in code-projects Nero Social Networking Site 1.0. Affected by this issue is some unk...
CVE-2025-12307CRITICAL9.8A vulnerability was identified in code-projects Nero Social Networking Site 1.0. Affected by this vulnerability is an un...
CVE-2025-12306CRITICAL9.8A vulnerability was determined in code-projects Nero Social Networking Site 1.0. Affected is an unknown function of the ...
CVE-2025-12305CRITICAL9.8A vulnerability was found in quequnlong shiyi-blog up to 1.2.1. This impacts an unknown function of the file src/main/ja...
CVE-2025-12304MEDIUM4.3A vulnerability has been found in dulaiduwang003 TIME-SEA-PLUS up to fb299162f18498dd9cf17da906886d80a077d53b. This affe...
CVE-2025-61795MEDIUM5.3Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits)...
CVE-2025-61385CRITICAL9.6SQL injection vulnerability in tlocke pg8000 1.31.4 allows remote attackers to execute arbitrary SQL commands via a spec...
CVE-2025-60983MEDIUM5.4Reflected Cross Site Scripting vulnerability in Rubikon Banking Solution 4.0.3 in the "Search For Customers Information"...
CVE-2025-60982MEDIUM5.4IDOR vulnerability in Educare ERP 1.0 (2025-04-22) allows unauthorized access to sensitive data via manipulated object r...
CVE-2025-55754CRITICAL9.6Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANS...
CVE-2025-55752HIGH7.5Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the r...
CVE-2025-54965MEDIUM6.1An XSS issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not properly sanitize...
CVE-2025-12364CRITICAL9.8Weak Password Policy.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12363HIGH7.5Email Password Disclosure.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5.
CVE-2025-12303MEDIUM4.8A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. The impacted element is an unknown function of ...
CVE-2025-12302MEDIUM6.1A vulnerability was detected in code-projects Simple Food Ordering System 1.0. The affected element is an unknown functi...
CVE-2025-12301CRITICAL9.8A security vulnerability has been detected in code-projects Simple Food Ordering System 1.0. Impacted is an unknown func...
CVE-2025-12300MEDIUM6.1A weakness has been identified in code-projects Simple Food Ordering System 1.0. This issue affects some unknown process...
CVE-2025-54970MEDIUM6.5An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service fails to authenticate requests...
CVE-2025-54969MEDIUM6.1An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Status Service does not implement CSRF protec...
CVE-2025-54968HIGH8.8An issue was discovered in BAE SOCET GXP before 4.6.0.2. The SOCET GXP Job Service does not require authentication. In s...
CVE-2025-54967MEDIUM6.5An issue was discovered in BAE SOCET GXP before 4.6.0.3. It permits external entities in certain XML-based files. An att...
CVE-2025-27225HIGH7.5TRUfusion Enterprise through 7.10.4.0 exposes the /trufusionPortal/jsp/internal_admin_contact_login.jsp endpoint to unau...
CVE-2025-27224CRITICAL9.8TRUfusion Enterprise through 7.10.4.0 uses the /trufusionPortal/fileupload endpoint to upload files. However, the applic...
CVE-2025-27223HIGH7.5TRUfusion Enterprise through 7.10.4.0 exposes the encrypted COOKIEID as an authentication mechanism for some endpoints s...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now