2025 CVE Vulnerabilities

45,206 CVEs published in 2025.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2025-26372HIGH8.1A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2...
CVE-2025-26371HIGH8.8A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2...
CVE-2025-26370HIGH7.1A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2...
CVE-2025-26369HIGH8.8A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2...
CVE-2025-26368HIGH8.1A CWE-862 "Missing Authorization" in maxprofile/user-groups/routes.lua in Q-Free MaxTime less than or equal to version 2...
CVE-2025-26366HIGH7.5A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26365HIGH7.5A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26364HIGH7.5A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26363HIGH7.5A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26362HIGH7.5A CWE-306 "Missing Authentication for Critical Function" in maxprofile/setup/routes.lua in Q-Free MaxTime less than or e...
CVE-2025-26356HIGH7.2A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (setActive endpoint) in Q-Free MaxTime less than or equal...
CVE-2025-26354HIGH7.2A CWE-35 "Path Traversal" in maxtime/api/database/database.lua (copy endpoint) in Q-Free MaxTime less than or equal to v...
CVE-2025-26350HIGH8.8A CWE-434 "Unrestricted Upload of File with Dangerous Type" in the template file uploads in Q-Free MaxTime less than or ...
CVE-2025-26349HIGH7.2A CWE-23 "Relative Path Traversal" in the file upload mechanism in Q-Free MaxTime less than or equal to version 2.11.0 a...
CVE-2025-26348HIGH7.6A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model...
CVE-2025-26346HIGH7.6A CWE-89 "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')" in maxprofile/menu/model...
CVE-2025-26343HIGH8.1A CWE-1390 "Weak Authentication" in the PIN authentication mechanism in Q-Free MaxTime less than or equal to version 2.1...
CVE-2025-26340HIGH8.8A CWE-321 "Use of Hard-coded Cryptographic Key" in the JWT signing in Q-Free MaxTime less than or equal to version 2.11....
CVE-2025-1200HIGH8.8A vulnerability was found in SourceCodester Best Church Management Software 1.1. It has been declared as critical. This ...
CVE-2025-1102HIGH7.1A CWE-346 "Origin Validation Error" in the CORS configuration in Q-Free MaxTime less than or equal to version 2.11.0 all...
CVE-2025-1197HIGH7.5A vulnerability has been found in code-projects Real Estate Property Management System 1.0 and classified as critical. A...
CVE-2025-1192HIGH8.8A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0. It has been classified as cri...
CVE-2025-1191HIGH8.8A vulnerability was found in SourceCodester Multi Restaurant Table Reservation System 1.0 and classified as critical. Th...
CVE-2025-1189HIGH8.8A vulnerability, which was classified as critical, was found in 1000 Projects Attendance Tracking Management System 1.0....
CVE-2025-1187HIGH7.8A vulnerability classified as critical was found in code-projects Police FIR Record Management System 1.0. Affected by t...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now