2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-52389HIGH8.8An Insecure Direct Object Reference (IDOR) in Envasadora H2O Eireli - Soda Cristal v40.20.4 allows authenticated attacke...
CVE-2025-10104CRITICAL9.8A security vulnerability has been detected in code-projects Online Event Judging System 1.0. Affected is an unknown func...
CVE-2025-9114CRITICAL9.8The Doccure theme for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 1.5.0....
CVE-2025-9113CRITICAL9.8The Doccure Core plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the...
CVE-2025-9112HIGH8.8The Doccure theme for WordPress is vulnerable to arbitrary file uploads due to incorrect file type validation in the 'do...
CVE-2025-55849HIGH8.4WeiPHP v5.0 and before is vulnerable to SQL Injection via the SucaiController.class.php file and the cancelTemplatee
CVE-2025-43722MEDIUM6.7Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper privilege management vulnerability. A high privi...
CVE-2025-10103CRITICAL9.8A weakness has been identified in code-projects Online Event Judging System 1.0. This impacts an unknown function of the...
CVE-2025-10102CRITICAL9.8A security flaw has been discovered in code-projects Online Event Judging System 1.0. This affects an unknown function o...
CVE-2025-57285CRITICAL9.8codeceptjs 3.7.3 contains a command injection vulnerability in the emptyFolder function (lib/utils.js). The execSync com...
CVE-2025-56267CRITICAL9.8A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitr...
CVE-2025-56266CRITICAL9.8A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplyin...
CVE-2025-56265HIGH8.8An arbitrary file upload vulnerability in the Chat Trigger component of N8N v1.95.3, v1.100.1, and v1.101.1 allows attac...
CVE-2025-10100CRITICAL9.8A vulnerability was detected in SourceCodester Simple Forum Discussion System 1.0. This impacts an unknown function of t...
CVE-2025-10099MEDIUM4.8A weakness has been identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functiona...
CVE-2025-51586LOW3.7An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers ...
CVE-2025-10098HIGH8.8A security flaw has been discovered in PHPGurukul User Management System 1.0. Affected is an unknown function of the fil...
CVE-2025-10097CRITICAL9.8A vulnerability was identified in SimStudioAI sim up to 1.0.0. This impacts an unknown function of the file apps/sim/app...
CVE-2025-10096MEDIUM6.5A vulnerability was determined in SimStudioAI sim up to 1.0.0. This affects an unknown function of the file apps/sim/app...
CVE-2025-7709MEDIUM6.9An integer overflow exists in the FTS5 https://sqlite.org/fts5.html  extension. It occurs when the size of an array of ...
CVE-2025-59033HIGH7.4The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries...
CVE-2025-57141CRITICAL9.8rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
CVE-2025-56630HIGH7.3FoxCMS v1.2.5 and before is vulnerable to SQL Injection via the column_model parameter in the app/admin/controller/Colum...
CVE-2025-55998HIGH8.1A cross-site scripting (XSS) vulnerability in Smart Search & Filter Shopify and BigCommerce apps allows a remote attacke...
CVE-2025-52161CRITICAL9.8Scholl Communications AG Weblication CMS Core v019.004.000.000 was discovered to contain a cross-site scripting (XSS) vu...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now