2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26615HIGH7.5WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnera...
CVE-2025-26614HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26605HIGH8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerab...
CVE-2025-26604HIGH8.3Discord-Bot-Framework-Kernel is a Discord bot framework built with interactions.py, featuring modular extension manageme...
CVE-2025-22663HIGH8.6Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in videowhisper Paid Videoc...
CVE-2025-22657HIGH7.5Missing Authorization vulnerability in Vito Peleg Atarim atarim-visual-collaboration allows Exploiting Incorrectly Confi...
CVE-2025-22656HIGH8.1Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in...
CVE-2025-22639HIGH8.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Techspawn Distance...
CVE-2025-25305HIGH7Home Assistant Core is an open source home automation that puts local control and privacy first. Affected versions are s...
CVE-2025-25284HIGH8.7The ZOO-Project is an open source processing platform, released under MIT/X11 Licence. A vulnerability in ZOO-Project's ...
CVE-2025-21703HIGH7.8In the Linux kernel, the following vulnerability has been resolved: netem: Update sch->q.qlen before qdisc_tree_reduce_...
CVE-2025-21702HIGH7In the Linux kernel, the following vulnerability has been resolved: pfifo_tail_enqueue: Drop new packet when sch->limit...
CVE-2025-0425HIGH8.5Via the GUI of the "bestinformed Infoclient", a low-privileged user is by default able to change the server address of t...
CVE-2025-0422HIGH8.6An authenticated user in the "bestinformed Web" application can execute commands on the underlying server running the ap...
CVE-2025-25224HIGH7.5The LuxCal Web Calendar prior to 5.3.3M (MySQL version) and prior to 5.3.3L (SQLite version) contains a missing authenti...
CVE-2025-20075HIGH7.2Server-side request forgery (SSRF) vulnerability exists in FileMegane versions above 3.0.0.0 prior to 3.4.0.0. Executing...
CVE-2025-21103HIGH7.8Dell NetWorker Management Console, version(s) 19.11 through 19.11.0.3 & Versions prior to 19.10.0.7 contain(s) an improp...
CVE-2025-26773HIGH8.8Missing Authorization vulnerability in Adnan Analytify wp-analytify allows Exploiting Incorrectly Configured Access Cont...
CVE-2025-23845HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ERA404 ImageMeta i...
CVE-2025-23840HIGH7.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webjema WP-NOTCAPT...
CVE-2025-1381HIGH7.5A vulnerability was found in code-projects Real Estate Property Management System 1.0. It has been classified as critica...
CVE-2025-1389HIGH8.8Orca HCM from Learning Digital has a SQL Injection vulnerability, allowing attackers with regular privileges to inject a...
CVE-2025-1388HIGH8.8Orca HCM from LEARNING DIGITAL has an Arbitrary File Upload vulnerability, allowing remote attackers with regular privil...
CVE-2025-1374HIGH7.5A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. This ...
CVE-2025-1372HIGH7.8A vulnerability was found in GNU elfutils 0.192. It has been declared as critical. Affected by this vulnerability is the...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now