2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-61780MEDIUM5.3Rack is a modular Ruby web server interface. Prior to versions 2.2.20, 3.1.18, and 3.2.3, a possible information disclos...
CVE-2025-61689HIGH8.7HTTP.jl is an HTTP client and server functionality for the Julia programming language. Prior to version 1.10.19, HTTP.jl...
CVE-2025-60308MEDIUM4.1code-projects Simple Online Hotel Reservation System 1.0 has a Cross Site Scripting (XSS) vulnerability in the Add Room ...
CVE-2025-60306CRITICAL9.9code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil...
CVE-2025-60269CRITICAL9.4JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework...
CVE-2025-60307CRITICAL9.8code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in t...
CVE-2025-60305HIGH8.8SourceCodester Online Student Clearance System 1.0 is vulnerable to Incorrect Access Control. The application contains a...
CVE-2025-59530HIGH7.5quic-go is an implementation of the QUIC protocol in Go. In versions prior to 0.49.0, 0.54.1, and 0.55.0, a misbehaving ...
CVE-2025-48043HIGH8.6Incorrect Authorization vulnerability in ash-project ash allows Authentication Bypass. This vulnerability is associated ...
CVE-2025-60869HIGH7.3Publii CMS v0.46.5 (build 17089) allows persistent Cross-Site Scripting (XSS) via unsanitized input in configuration fie...
CVE-2025-60378HIGH8.1Stored HTML injection in RISE Ultimate Project Manager & CRM allows authenticated users to inject arbitrary HTML into in...
CVE-2025-8887MEDIUM6.1Authorization Bypass Through User-Controlled Key, Missing Authorization, Exposure of Sensitive Information to an Unautho...
CVE-2025-8886MEDIUM6.7Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missi...
CVE-2025-61319MEDIUM6.1ReNgine thru 2.2.0 is vulnerable to a Stored Cross-Site Scripting (XSS) vulnerability in the Vulnerabilities module. Whe...
CVE-2025-61152MEDIUM6.5python-jose thru 3.3.0 allows JWT tokens with 'alg=none' to be decoded and accepted without any cryptographic signature ...
CVE-2025-60868MEDIUM6.5The Alt Redirect 1.6.3 addon for Statamic fails to consistently strip query string parameters when the "Query String Str...
CVE-2025-62239MEDIUM5.4Cross-site scripting (XSS) vulnerability in workflow process builder in Liferay Portal 7.4.3.21 through 7.4.3.111, and L...
CVE-2025-62238MEDIUM5.4Stored cross-site scripting (XSS) vulnerability on the Membership page in Account Settings in Liferay Portal 7.4.3.21 th...
CVE-2025-62237MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in Commerce’s view order page in Liferay Portal 7.4.3.8 through 7.4.3.11...
CVE-2025-7781MEDIUM6.4The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to Stored Cross-Site Scripting via the ‘...
CVE-2025-7374MEDIUM5.4The WP JobHunt plugin for WordPress, used by the JobCareer theme, is vulnerable to authorization bypass in all versions ...
CVE-2025-11579MEDIUM6.5github.com/nwaples/rardecode versions <=2.1.1 fail to restrict the dictionary size when reading large RAR dictionary siz...
CVE-2025-61864HIGH8.4A use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially craft...
CVE-2025-61863HIGH8.4An out-of-bounds read vulnerability exists in VS6ComFile!CSaveData::delete_mem of V-SFT v6.2.7.0 and earlier. Opening sp...
CVE-2025-61862HIGH8.4An out-of-bounds read vulnerability exists in VS6ComFile!get_ovlp_element_size of V-SFT v6.2.7.0 and earlier. Opening sp...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now