2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11630 | CRITICAL | 9.8 | 0.6% | Oct 12, 2025 | A vulnerability was found in RainyGao DocSys up to 2.02.36. Affected is the function updateRealDoc of the file /Doc/uplo... |
| CVE-2025-11629 | CRITICAL | 9.8 | 0.4% | Oct 12, 2025 | A vulnerability has been found in RainyGao DocSys up to 2.02.36. This impacts the function getUserList of the file /Mana... |
| CVE-2025-31998 | CRITICAL | 9.8 | 0.4% | Oct 12, 2025 | HCL Unica Centralized Offer Management is vulnerable to poor unhandled exceptions which exposes sensitive information. ... |
| CVE-2025-31993 | CRITICAL | 9.8 | 0.2% | Oct 12, 2025 | HCL Unica Centralized Offer Management is vulnerable to a potential Server-Side Request Forgery (SSRF). An attacker can ... |
| CVE-2025-11615 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A security flaw has been discovered in SourceCodester Best Salon Management System 1.0. This affects an unknown part of ... |
| CVE-2025-11614 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was identified in SourceCodester Best Salon Management System 1.0. Affected by this issue is some unknow... |
| CVE-2025-11608 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A security vulnerability has been detected in code-projects E-Banking System 1.0. This affects an unknown function of th... |
| CVE-2025-11604 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was determined in projectworlds Online Ordering Food System 1.0. This issue affects some unknown process... |
| CVE-2025-11601 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an un... |
| CVE-2025-11599 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown func... |
| CVE-2025-11597 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of t... |
| CVE-2025-6439 | CRITICAL | 9.8 | 0.7% | Oct 11, 2025 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the... |
| CVE-2025-11596 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of t... |
| CVE-2025-11595 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function o... |
| CVE-2025-6553 | CRITICAL | 9.8 | 0.7% | Oct 11, 2025 | The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2025-11533 | CRITICAL | 9.8 | 0.6% | Oct 11, 2025 | The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. T... |
| CVE-2025-11586 | CRITICAL | 9.8 | 0.8% | Oct 10, 2025 | A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgr... |
| CVE-2025-11585 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of... |
| CVE-2025-11584 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown functio... |
| CVE-2025-61929 | CRITICAL | 9.6 | 0.4% | Oct 10, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol ca... |
| CVE-2025-11583 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjo... |
| CVE-2025-11582 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing o... |
| CVE-2025-60306 | CRITICAL | 9.9 | 0.4% | Oct 10, 2025 | code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil... |
| CVE-2025-60269 | CRITICAL | 9.4 | 0.3% | Oct 10, 2025 | JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework... |
| CVE-2025-60307 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now