2025 CVE Vulnerabilities

45,224 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11476CRITICAL9.8A vulnerability was identified in SourceCodester Simple E-Commerce Bookstore 1.0. This affects an unknown part of the fi...
CVE-2025-60299MEDIUM5.4Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addComme...
CVE-2025-60298MEDIUM5.4Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updat...
CVE-2025-43821MEDIUM5.4Cross-site scripting (XSS) vulnerability in the Commerce Product Comparison Table widget in Liferay Portal 7.4.0 through...
CVE-2025-11475CRITICAL9.8A vulnerability was determined in projectworlds Advanced Library Management System 1.0. Affected by this issue is some u...
CVE-2025-11474CRITICAL9.8A vulnerability was found in SourceCodester Hotel and Lodge Management System 1.0. Affected by this vulnerability is an ...
CVE-2025-11473CRITICAL9.8A vulnerability has been found in SourceCodester Hotel and Lodge Management System 1.0. Affected is an unknown function ...
CVE-2025-11472CRITICAL9.8A flaw has been found in SourceCodester Hotel and Lodge Management System 1.0. This impacts an unknown function of the f...
CVE-2025-11471CRITICAL9.8A vulnerability was detected in SourceCodester Hotel and Lodge Management System 1.0. This affects an unknown function o...
CVE-2025-10649MEDIUM6.5The Welcart e-Commerce plugin for WordPress is vulnerable to SQL Injection via the cookie in all versions up to, and inc...
CVE-2025-10353CRITICAL9.3File upload leading to remote code execution (RCE) in the “melis-cms-slider” module of Melis Technology's Melis Platform...
CVE-2025-10352CRITICAL9.3Vulnerability in the melis-core module of Melis Technology's Melis Platform, which, if exploited, allows an unauthentica...
CVE-2025-10351CRITICAL9.3SQL injection vulnerability based on the melis-cms module of the Melis platform from Melis Technology. This vulnerabilit...
CVE-2025-11470HIGH7.2A security vulnerability has been detected in SourceCodester Hotel and Lodge Management System up to 1.0. The impacted e...
CVE-2025-11469CRITICAL9.8A weakness has been identified in SourceCodester Hotel and Lodge Management System 1.0. The affected element is an unkno...
CVE-2025-11445MEDIUM6.3A vulnerability was detected in Kilo Code up to 4.86.0. Affected is the function ClineProvider of the file src/core/webv...
CVE-2025-11444HIGH8.8A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function set...
CVE-2025-11443MEDIUM5.9A weakness has been identified in JhumanJ OpnForm up to 1.9.3. This affects an unknown function of the file /api/passwor...
CVE-2025-11442MEDIUM4.3A security flaw has been discovered in JhumanJ OpnForm up to 1.9.3. The impacted element is an unknown function of the c...
CVE-2025-48464MEDIUM4.7Successful exploitation of the vulnerability could allow an unauthenticated attacker to gain access to a victim’s Sync a...
CVE-2025-11441LOW3.7A vulnerability was identified in JhumanJ OpnForm up to 1.9.3. The affected element is an unknown function of the compon...
CVE-2025-11440MEDIUM4.3A vulnerability was determined in JhumanJ OpnForm up to 1.9.3. Impacted is an unknown function of the file /edit. Execut...
CVE-2025-11439MEDIUM4.3A vulnerability was found in JhumanJ OpnForm up to 1.9.3. This issue affects some unknown processing of the file /show/i...
CVE-2025-11438MEDIUM6.3A vulnerability has been found in JhumanJ OpnForm up to 1.9.3. This vulnerability affects unknown code of the file /cust...
CVE-2025-11437MEDIUM4.8A flaw has been found in JhumanJ OpnForm up to 1.9.3. This affects an unknown part of the file /api/open/forms/ of the c...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now