2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11041 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A vulnerability has been found in itsourcecode Open Source Job Portal 1.0. Affected by this issue is some unknown functi... |
| CVE-2025-11040 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability was detected in code-projects Hostel Management System 1.0. Affected by this issue is some unknown funct... |
| CVE-2025-11039 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A security vulnerability has been detected in Campcodes Computer Sales and Inventory System 1.0. Affected by this vulner... |
| CVE-2025-11038 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in itsourcecode Online Clinic Management System 1.0. Affected is an unknown function of t... |
| CVE-2025-11037 | CRITICAL | 9.8 | 0.5% | Sep 26, 2025 | A security flaw has been discovered in code-projects E-Commerce Website 1.0. This impacts an unknown function of the fil... |
| CVE-2025-11036 | CRITICAL | 9.8 | 0.5% | Sep 26, 2025 | A vulnerability was identified in code-projects E-Commerce Website 1.0. This affects an unknown function of the file /pa... |
| CVE-2025-11035 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability was determined in Jinher OA 2.0. The impacted element is an unknown function of the file /c6/Jhsoft.Web.... |
| CVE-2025-58384 | CRITICAL | 10 | 0.7% | Sep 26, 2025 | In DOXENSE WATCHDOC before 6.1.1.5332, Deserialization of Untrusted Data can lead to remote code execution through the .... |
| CVE-2025-56383 | HIGH | 8.4 | 0.3% | Sep 26, 2025 | Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. N... |
| CVE-2025-55847 | HIGH | 8.8 | 1.9% | Sep 26, 2025 | Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerab... |
| CVE-2025-45994 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a... |
| CVE-2025-11034 | MEDIUM | 4.3 | 0.4% | Sep 26, 2025 | A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function download... |
| CVE-2025-11033 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A vulnerability has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Impacted ... |
| CVE-2025-11032 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A flaw has been found in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This issue affects... |
| CVE-2025-59844 | HIGH | 7.7 | 1.5% | Sep 26, 2025 | SonarQube Server and Cloud is a static analysis solution for continuous code quality and security inspection. A command ... |
| CVE-2025-55848 | HIGH | 8.8 | 0.4% | Sep 26, 2025 | An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interfa... |
| CVE-2025-26258 | MEDIUM | 6.1 | 0.2% | Sep 26, 2025 | Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.' |
| CVE-2025-11031 | MEDIUM | 5.5 | 0.8% | Sep 26, 2025 | A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/res... |
| CVE-2025-11030 | HIGH | 7.3 | 0.4% | Sep 26, 2025 | A vulnerability was detected in Tutorials-Website Employee Management System up to 611887d8f8375271ce8abc704507d46340837... |
| CVE-2025-11029 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in givanz Vvveb up to 1.0.7.2. This vulnerability affects unknown code. Executing manipul... |
| CVE-2025-59843 | MEDIUM | 5.3 | 0.4% | Sep 26, 2025 | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[use... |
| CVE-2025-59842 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... |
| CVE-2025-59362 | MEDIUM | 4 | 0.4% | Sep 26, 2025 | Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c. |
| CVE-2025-58385 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | In DOXENSE WATCHDOC before 6.1.0.5094, private user puk codes can be disclosed for Active Directory registered users (th... |
| CVE-2025-56463 | MEDIUM | 6.8 | 0.2% | Sep 26, 2025 | Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now