2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10598CRITICAL9.8A vulnerability was identified in SourceCodester Pet Grooming Management Software 1.0. This issue affects some unknown p...
CVE-2025-10597CRITICAL9.8A vulnerability was determined in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. This vuln...
CVE-2025-9862MEDIUM6.5Server-Side Request Forgery (SSRF) vulnerability in Ghost allows an attacker to access internal resources.This issue aff...
CVE-2025-57055MEDIUM6.5WonderCMS 3.5.0 is vulnerable to Server-Side Request Forgery (SSRF) in the custom module installation functionality. An ...
CVE-2025-54390MEDIUM6.3A Cross-Site Request Forgery (CSRF) vulnerability exists in the ResetPasswordRequest operation of Zimbra Collaboration (...
CVE-2025-40933HIGH7.5Apache::AuthAny::Cookie v0.201 or earlier for Perl generates session ids insecurely. Session ids are generated using an...
CVE-2025-10596CRITICAL9.8A vulnerability was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /i...
CVE-2025-10595HIGH8.8A vulnerability has been found in SourceCodester Online Student File Management System 1.0. Affected by this issue is so...
CVE-2025-10205HIGH8.8Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through 9.3.5. and ...
CVE-2025-59476MEDIUM5.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not restrict or transform the characters that can be inserted fr...
CVE-2025-59475MEDIUM4.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check for the authenticated user profil...
CVE-2025-59474MEDIUM5.3Jenkins 2.527 and earlier, LTS 2.516.2 and earlier does not perform a permission check in the sidepanel of a page intent...
CVE-2025-55904MEDIUM4Open5GS v2.7.5, prior to commit 67ba7f92bbd7a378954895d96d9d7b05d5b64615, is vulnerable to a NULL pointer dereference wh...
CVE-2025-50709MEDIUM4.3An issue in Perplexity AI GPT-4 allows a remote attacker to obtain sensitive information via a GET parameter
CVE-2025-10594HIGH8.8A flaw has been found in SourceCodester Online Student File Management System 1.0. Affected by this vulnerability is an ...
CVE-2025-10593HIGH8.8A vulnerability was detected in SourceCodester Online Student File Management System 1.0. Affected is an unknown functio...
CVE-2025-8463MEDIUM5.3Authorization Bypass Through User-Controlled Key vulnerability in SecHard Information Technologies SecHard allows Forcef...
CVE-2025-8077CRITICAL9.8A vulnerability exists in NeuVector versions up to and including 5.4.5, where a fixed string is used as the default pass...
CVE-2025-54467MEDIUM5.3When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the pass...
CVE-2025-53884MEDIUM5.3NeuVector stores user passwords and API keys using a simple, unsalted hash. This method is vulnerable to rainbow table a...
CVE-2025-10592HIGH8.8A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknow...
CVE-2025-0879MEDIUM4.7Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Shopside So...
CVE-2025-8999MEDIUM5.3The Sydney theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t...
CVE-2025-8411HIGH7.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dokuzsoft T...
CVE-2025-10439CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Yordam Informatics...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now