2025 CVE Vulnerabilities

45,142 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-30035CRITICAL9The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ...
CVE-2025-10350HIGH8.8SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attack...
CVE-2025-15597MEDIUM6.3A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps...
CVE-2025-13673HIGH7.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon...
CVE-2025-69437HIGH8.7PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ...
CVE-2025-15498CRITICAL9.3Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ...
CVE-2025-10990HIGH7.5A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin...
CVE-2025-11950MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Adva...
CVE-2025-11252CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ...
CVE-2025-11251CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I...
CVE-2025-14142MEDIUM6.4The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t...
CVE-2025-12150LOW3.1A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf...
CVE-2025-9909MEDIUM6.7A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows ...
CVE-2025-9908MEDIUM6.7A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerabilit...
CVE-2025-9907MEDIUM6.7A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerabi...
CVE-2025-9572MEDIUM6.5n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi...
CVE-2025-13327MEDIUM6.3A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or ins...
CVE-2025-15567LOW3.3Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
CVE-2025-15509MEDIUM4.3The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2025-14149MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-14040MEDIUM6.4The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th...
CVE-2025-12981CRITICAL9.8The Listee theme for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.6. This i...
CVE-2025-40932HIGH8.2Apache::SessionX versions through 2.01 for Perl create insecure session id. Apache::SessionX generates session ids inse...
CVE-2025-11384Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-11383Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now