2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10673CRITICAL9.8A vulnerability was determined in itsourcecode Student Information Management System 1.0. The impacted element is an unk...
CVE-2025-10672HIGH7.8A vulnerability was found in whuan132 AIBattery up to 1.0.9. The affected element is an unknown function of the file AIB...
CVE-2025-10671LOW3.7A vulnerability has been found in youth-is-as-pale-as-poetry e-learning 1.0. Impacted is the function encryptSecret of t...
CVE-2025-4444MEDIUM6.3A security flaw has been discovered in Tor up to 0.4.7.16/0.4.8.17. Impacted is an unknown function of the component Oni...
CVE-2025-10670CRITICAL9.8A flaw has been found in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. This issue affects some ...
CVE-2025-10669MEDIUM6.3A vulnerability was detected in Airsonic-Advanced up to 10.6.0. This vulnerability affects unknown code of the component...
CVE-2025-10668CRITICAL9.8A security vulnerability has been detected in itsourcecode Online Discussion Forum 1.0. This affects an unknown part of ...
CVE-2025-10667CRITICAL9.8A weakness has been identified in itsourcecode Online Discussion Forum 1.0. Affected by this issue is some unknown funct...
CVE-2025-10666CRITICAL9.8A security flaw has been discovered in D-Link DIR-825 up to 2.10. Affected by this vulnerability is the function sub_410...
CVE-2025-40678MEDIUM5.3Unrestricted upload vulnerability for dangerous file types on Summar Software´s Portal del Empleado. This vulnerability ...
CVE-2025-40677HIGH8.7SQL injection vulnerability in Summar Software´s Portal del Empleado. This vulnerability allows an attacker to retrieve,...
CVE-2025-10665CRITICAL9.8A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. Affected ...
CVE-2025-10664CRITICAL9.8A vulnerability was determined in PHPGurukul Small CRM 4.0. This impacts an unknown function of the file /create-ticket....
CVE-2025-10207HIGH7.5Improper Validation of Specified Type of Input vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5.
CVE-2025-10663CRITICAL9.8A vulnerability was found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /my...
CVE-2025-10662CRITICAL9.8A vulnerability has been found in SeaCMS up to 13.3. The impacted element is an unknown function of the file /admin_memb...
CVE-2025-9992MEDIUM6.4The Ghost Kit – Page Builder Blocks, Motion Effects & Extensions plugin for WordPress is vulnerable to Stored Cross-Site...
CVE-2025-8565HIGH8.1The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul...
CVE-2025-30187LOW3.7In some circumstances, when DNSdist is configured to use the nghttp2 library to process incoming DNS over HTTPS queries,...
CVE-2025-6237CRITICAL9.8A vulnerability in invokeai version v6.0.0a1 and below allows attackers to perform path traversal and arbitrary file del...
CVE-2025-0547MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Paraşüt Sof...
CVE-2025-10493MEDIUM5.3The Chained Quiz plugin for WordPress is vulnerable to Insecure Direct Object Reference in version 1.3.4 and below via t...
CVE-2025-9083CRITICAL9.8The Ninja Forms WordPress plugin before 3.11.1 unserializes user input via form field, which could allow Unauthenticate...
CVE-2025-8942CRITICAL9.1The WP Hotel Booking WordPress plugin before 2.2.3 lacks proper server-side validation for review ratings, allowing an a...
CVE-2025-5305CRITICAL9.8The Password Reset with Code for WordPress REST API WordPress plugin before 0.0.17 does not use cryptographically sound ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now