2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50199 | CRITICAL | 9.1 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a blind SSRF vulnerability in /index.php via... |
| CVE-2025-50198 | MEDIUM | 4.9 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, Chamilo is vulnerable to deserialization of untrusted... |
| CVE-2025-50197 | HIGH | 7.2 | 2.7% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma... |
| CVE-2025-50196 | HIGH | 7.2 | 2.7% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl... |
| CVE-2025-50195 | HIGH | 7.2 | 2.7% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /pl... |
| CVE-2025-50194 | HIGH | 7.2 | 2.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS Command Injection vulnerability in /ma... |
| CVE-2025-50193 | HIGH | 7.2 | 2.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an OS command Injection vulnerability in /pl... |
| CVE-2025-65465 | MEDIUM | 6.1 | 0.4% | Mar 2, 2026 | A reflected Cross-Site Scripting (XSS) vulnerability in the RaiseError function of Skrol29 TbsZip version 2.17 and earli... |
| CVE-2025-58107 | HIGH | 7.5 | 0.3% | Mar 2, 2026 | In Microsoft Exchange through 2019, Exchange ActiveSync (EAS) configurations on on-premises servers may transmit sensiti... |
| CVE-2025-52482 | HIGH | 8.3 | 0.4% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a Stored XSS vulnerability exists in the glossary fun... |
| CVE-2025-50192 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is a time-based SQL Injection in found in /main... |
| CVE-2025-50191 | HIGH | 7.2 | 0.5% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via POST userFi... |
| CVE-2025-50190 | CRITICAL | 9.8 | 0.6% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, there is an error-based SQL Injection via the GET ope... |
| CVE-2025-50189 | HIGH | 8.8 | 0.7% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d... |
| CVE-2025-50188 | HIGH | 7.2 | 0.7% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, the application performs insufficient validation of d... |
| CVE-2025-50187 | CRITICAL | 9.8 | 0.9% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.28, parameter from SOAP request is evaluated without filt... |
| CVE-2025-50186 | MEDIUM | 4.8 | 0.3% | Mar 2, 2026 | Chamilo is a learning management system. Prior to version 1.11.30, a stored cross-site scripting (XSS) vulnerability exi... |
| CVE-2025-14532 | CRITICAL | 9.8 | 0.5% | Mar 2, 2026 | DobryCMS's upload file functionality allows an unauthenticated remote attacker to upload files of any type and extension... |
| CVE-2025-12462 | CRITICAL | 9.3 | 0.4% | Mar 2, 2026 | A Blind SQL injection vulnerability has been identified in DobryCMS. A remote unauthenticated attacker is able to injec... |
| CVE-2025-58406 | MEDIUM | 4.3 | 0.2% | Mar 2, 2026 | The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such... |
| CVE-2025-58405 | MEDIUM | 6.1 | 0.2% | Mar 2, 2026 | The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security ... |
| CVE-2025-58402 | HIGH | 7.5 | 0.2% | Mar 2, 2026 | The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks.... |
| CVE-2025-30062 | MEDIUM | 6.9 | 0.2% | Mar 2, 2026 | In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection. |
| CVE-2025-30044 | CRITICAL | 9.4 | 0.5% | Mar 2, 2026 | In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-... |
| CVE-2025-30042 | HIGH | 7.8 | 0.1% | Mar 2, 2026 | The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now