2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10798 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A vulnerability was identified in code-projects Hostel Management System 1.0. Impacted is an unknown function of the fil... |
| CVE-2025-10797 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A vulnerability was determined in code-projects Hostel Management System 1.0. This issue affects some unknown processing... |
| CVE-2025-10796 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A vulnerability was found in code-projects Hostel Management System 1.0. This vulnerability affects unknown code of the ... |
| CVE-2025-9983 | HIGH | 7.1 | 0.6% | Sep 22, 2025 | GALAYOU G2 cameras stream video output via RTSP streams. By default these streams are protected by randomly generated cr... |
| CVE-2025-46711 | MEDIUM | 5.5 | 0.1% | Sep 22, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger NULL pointer derefe... |
| CVE-2025-10795 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A vulnerability has been found in code-projects Online Bidding System 1.0. This affects an unknown part of the file /adm... |
| CVE-2025-10794 | MEDIUM | 6.1 | 0.4% | Sep 22, 2025 | A flaw has been found in PHPGurukul Car Rental Project 3.0. Affected by this issue is some unknown functionality of the ... |
| CVE-2025-9035 | MEDIUM | 5.4 | 0.3% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Horato Inte... |
| CVE-2025-25177 | MEDIUM | 5.1 | 0.1% | Sep 22, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kern... |
| CVE-2025-10793 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A vulnerability was detected in code-projects E-Commerce Website 1.0. Affected by this vulnerability is an unknown funct... |
| CVE-2025-10792 | HIGH | 8.8 | 3.0% | Sep 22, 2025 | A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /gofor... |
| CVE-2025-10009 | HIGH | 8.6 | 0.5% | Sep 22, 2025 | Incorrect handling of uploaded files in the admin "Restore" function in Invoice Ninja <= 5.11.72 allows attackers with a... |
| CVE-2025-8079 | MEDIUM | 4.6 | 0.2% | Sep 22, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akıllı Tica... |
| CVE-2025-10791 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A weakness has been identified in code-projects Online Bidding System 1.0. This impacts an unknown function of the file ... |
| CVE-2025-10790 | HIGH | 8.8 | 0.3% | Sep 22, 2025 | A security flaw has been discovered in SourceCodester Simple Forum Discussion System 1.0. This affects an unknown functi... |
| CVE-2025-5962 | HIGH | 7.7 | 0.2% | Sep 22, 2025 | A flaw was found in the Lightspeed history service. Insufficient access controls allow a local, unprivileged user to acc... |
| CVE-2025-10789 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A vulnerability was identified in SourceCodester Online Hotel Reservation System 1.0. The impacted element is an unknown... |
| CVE-2025-10788 | CRITICAL | 9.8 | 0.4% | Sep 22, 2025 | A vulnerability was determined in SourceCodester Online Hotel Reservation System 1.0. The affected element is an unknown... |
| CVE-2025-0875 | MEDIUM | 6.5 | 0.4% | Sep 22, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in PROLIZ Computer Software Hardware Service Trade Ltd. C... |
| CVE-2025-10787 | MEDIUM | 6.3 | 0.2% | Sep 22, 2025 | A vulnerability was found in MuYuCMS up to 2.7. Impacted is an unknown function of the file /index/index.html of the com... |
| CVE-2025-10786 | CRITICAL | 9.8 | 0.5% | Sep 22, 2025 | A flaw has been found in Campcodes Grocery Sales and Inventory System 1.0. This vulnerability affects unknown code of th... |
| CVE-2025-9541 | MEDIUM | 4.7 | 0.2% | Sep 22, 2025 | The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the ... |
| CVE-2025-9540 | MEDIUM | 4.7 | 0.2% | Sep 22, 2025 | The Markup Markdown WordPress plugin before 3.20.10 allows links to contain JavaScript which could allow users with the ... |
| CVE-2025-9487 | MEDIUM | 4.7 | 0.2% | Sep 22, 2025 | The Admin and Site Enhancements (ASE) WordPress plugin before 7.9.8 does not sanitise SVG files when uploaded via xmlrpc... |
| CVE-2025-9115 | MEDIUM | 5.6 | 0.2% | Sep 22, 2025 | The Etsy Shop WordPress plugin before 3.0.7 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now