2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-26372 | HIGH | 8.1 | 0.4% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2... |
| CVE-2025-26371 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2... |
| CVE-2025-26370 | HIGH | 7.1 | 0.4% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2... |
| CVE-2025-26369 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2... |
| CVE-2025-26368 | HIGH | 8.1 | 0.5% | Feb 12, 2025 | A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2... |
| CVE-2025-26366 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26365 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26364 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26363 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26362 | HIGH | 7.5 | 0.5% | Feb 12, 2025 | A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e... |
| CVE-2025-26356 | HIGH | 7.2 | 0.8% | Feb 12, 2025 | A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal... |
| CVE-2025-26354 | HIGH | 7.2 | 0.8% | Feb 12, 2025 | A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to v... |
| CVE-2025-26350 | HIGH | 8.8 | 0.8% | Feb 12, 2025 | A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or ... |
| CVE-2025-26349 | HIGH | 7.2 | 2.7% | Feb 12, 2025 | A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 a... |
| CVE-2025-26348 | HIGH | 7.6 | 0.6% | Feb 12, 2025 | A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model... |
| CVE-2025-26346 | HIGH | 7.6 | 0.6% | Feb 12, 2025 | A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model... |
| CVE-2025-26343 | HIGH | 8.1 | 0.8% | Feb 12, 2025 | A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.1... |
| CVE-2025-26340 | HIGH | 8.8 | 1.1% | Feb 12, 2025 | A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11.... |
| CVE-2025-1200 | HIGH | 8.8 | 0.6% | Feb 12, 2025 | A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been declared as critical. This ... |
| CVE-2025-1102 | HIGH | 7.1 | 0.1% | Feb 12, 2025 | A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 all... |
| CVE-2025-1197 | HIGH | 7.5 | 0.4% | Feb 12, 2025 | A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. A... |
| CVE-2025-1192 | HIGH | 8.8 | 0.3% | Feb 12, 2025 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as cri... |
| CVE-2025-1191 | HIGH | 8.8 | 0.5% | Feb 12, 2025 | A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. Th... |
| CVE-2025-1189 | HIGH | 8.8 | 0.4% | Feb 12, 2025 | A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0.... |
| CVE-2025-1187 | HIGH | 7.8 | 0.3% | Feb 12, 2025 | A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. Affected by t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now