2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-50199CRITICAL9.1Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via...
CVE-2025-50198MEDIUM4.9Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted...
CVE-2025-50197HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma...
CVE-2025-50196HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl...
CVE-2025-50195HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl...
CVE-2025-50194HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma...
CVE-2025-50193HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /pl...
CVE-2025-65465MEDIUM6.1A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earli...
CVE-2025-58107HIGH7.5In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensiti...
CVE-2025-52482HIGH8.3Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun...
CVE-2025-50192CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main...
CVE-2025-50191HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFi...
CVE-2025-50190CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope...
CVE-2025-50189HIGH8.8Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d...
CVE-2025-50188HIGH7.2Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d...
CVE-2025-50187CRITICAL9.8Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt...
CVE-2025-50186MEDIUM4.8Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi...
CVE-2025-14532CRITICAL9.8DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension...
CVE-2025-12462CRITICAL9.3A Blind SQL injection vulnerability has been identified in DobryCMS.  A remote unauthenticated attacker is able to injec...
CVE-2025-58406MEDIUM4.3The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such...
CVE-2025-58405MEDIUM6.1The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security ...
CVE-2025-58402HIGH7.5The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks....
CVE-2025-30062MEDIUM6.9In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.
CVE-2025-30044CRITICAL9.4In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-...
CVE-2025-30042HIGH7.8The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client d...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now