2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9970HIGH7.4Cleartext Storage of Sensitive Information in Memory vulnerability in ABB MConfig.This issue affects MConfig: through 1....
CVE-2025-53967HIGH8Framelink Figma MCP Server before 0.6.3 allows an unauthenticated remote attacker to execute arbitrary operating system ...
CVE-2025-11486CRITICAL9.8A vulnerability was identified in SourceCodester Farm Management System 1.0. Affected by this vulnerability is an unknow...
CVE-2025-11485MEDIUM4.8A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function add_user...
CVE-2025-11481CRITICAL9.8A flaw has been found in varunsardana004 Blood-Bank-And-Donation-Management-System up to dc9e0393d826fbc85fad9755b5bc12c...
CVE-2025-60318MEDIUM6.1SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) in /admin/profile.php vi...
CVE-2025-5009LOW1In Gemini iOS, when a user shared a snippet of a conversation, it would share the entire conversation via a sharable pub...
CVE-2025-59303MEDIUM6.4HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snipp...
CVE-2025-36636MEDIUM4.3In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticat...
CVE-2025-61672MEDIUM5.3Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3...
CVE-2025-60834MEDIUM6.5A fastjson deserialization vulnerability in uzy-ssm-mall v1.1.0 allows attackers to execute arbitrary code via supplying...
CVE-2025-60313MEDIUM6.1Sourcecodester Link Status Checker 1.0 is vulnerable to a Cross-Site Scripting (XSS) in the Enter URLs to check input fi...
CVE-2025-43771MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities in the Notifications widget in Liferay Portal 7.4.3.102 through 7.4....
CVE-2025-43724MEDIUM4.4Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an authorization bypass through user-controlled key vulnerab...
CVE-2025-11480CRITICAL9.8A vulnerability was detected in SourceCodester Simple E-Commerce Bookstore 1.0. The affected element is an unknown funct...
CVE-2025-11479CRITICAL9.8A security vulnerability has been detected in SourceCodester Wedding Reservation Management System 1.0. Impacted is the ...
CVE-2025-61183MEDIUM6.1Cross Site Scripting in vaahcms v.2.3.1 allows a remote attacker to execute arbitrary code via upload method in the stor...
CVE-2025-60833MEDIUM6.5An XML External Entity (XXE) vulnerability in the /mall/wxpay/pay component of uzy-ssm-mall v1.1.0 allows attackers to e...
CVE-2025-60830MEDIUM6.5redragon-erp v1.0 was discovered to contain a Shiro deserialization vulnerability caused by the default Shiro key.
CVE-2025-60828MEDIUM6.5WukongCRM-9.0-JAVA was discovered to contain a fastjson deserialization vulnerability via the /OaExamine/setOaExamine in...
CVE-2025-60314MEDIUM5.4Configuroweb Sistema Web de Inventario 1.0 is vulnerable to a Stored Cross-Site Scripting (XSS) due to the lack of input...
CVE-2025-43830MEDIUM6.1Stored cross-site scripting (XSS) vulnerability in Forms in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023...
CVE-2025-43829MEDIUM5.4Stored cross-site scripting (XSS) vulnerability in diagram type products in Commerce in Liferay Portal 7.4.3.18 through ...
CVE-2025-11478HIGH8.8A weakness has been identified in SourceCodester Farm Management System 1.0. This issue affects some unknown processing ...
CVE-2025-11477CRITICAL9.8A security flaw has been discovered in SourceCodester Wedding Reservation Management System 1.0. This vulnerability affe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now