2025 CVE Vulnerabilities
45,137 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-69945 | HIGH | 7.3 | — | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /doctor/edit-patient.php?editid=1. |
| CVE-2025-69944 | HIGH | 7.3 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in the view-medhistory.php endpoint via the vie... |
| CVE-2025-69943 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerale to SQL Injection in get_doctor.php via the parameters doctor and ... |
| CVE-2025-69942 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /hms/doctor/view-patient.php?viewid=1. |
| CVE-2025-67408 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in /save_user.php via the parameter ... |
| CVE-2025-67407 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_student.php via parameters... |
| CVE-2025-67406 | HIGH | 7.3 | — | Jul 29, 2026 | https://www.sourcecodester.com Advocate office management system 1.0 is affected by: SQL Injection. The impact is: execu... |
| CVE-2025-67405 | HIGH | 7.3 | — | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the param... |
| CVE-2025-67404 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters ... |
| CVE-2025-67403 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the paramete... |
| CVE-2025-65340 | CRITICAL | 9.8 | 0.1% | Jul 29, 2026 | kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. |
| CVE-2025-65337 | MEDIUM | 6.1 | 0.1% | Jul 29, 2026 | Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address ... |
| CVE-2025-14562 | LOW | 3.1 | 0.2% | Jul 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 1... |
| CVE-2025-60931 | HIGH | 7.5 | — | Jul 29, 2026 | An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33... |
| CVE-2025-10656 | CRITICAL | 9.8 | 0.5% | Jul 29, 2026 | The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Au... |
| CVE-2025-63913 | HIGH | 7.5 | 0.1% | Jul 27, 2026 | An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI fu... |
| CVE-2025-50455 | CRITICAL | 9.1 | 0.6% | Jul 27, 2026 | SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAp... |
| CVE-2025-59181 | MEDIUM | 4.8 | 0.3% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuratio... |
| CVE-2025-59180 | MEDIUM | 5.1 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm s... |
| CVE-2025-59178 | MEDIUM | 4.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnera... |
| CVE-2025-59177 | MEDIUM | 6.8 | 0.1% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowi... |
| CVE-2025-59172 | HIGH | 8.5 | 0.2% | Jul 27, 2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vuln... |
| CVE-2025-15662 | HIGH | 8.6 | — | Jul 27, 2026 | The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl... |
| CVE-2025-71408 | HIGH | 8.5 | 0.2% | Jul 24, 2026 | NLTK (Natural Language Toolkit) before version 3.9.3 contains an eval injection vulnerability in the nltk.collocations m... |
| CVE-2025-9205 | MEDIUM | 6.4 | 0.2% | Jul 24, 2026 | The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now