2025 CVE Vulnerabilities

45,251 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-41035MEDIUM6.5A problem has been discovered in appRain CMF 4.0.5. An authenticated Path Traversal vulnerability in /apprain/common/dow...
CVE-2025-41034CRITICAL9.8An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c...
CVE-2025-41033CRITICAL9.8An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c...
CVE-2025-41032CRITICAL9.8An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, c...
CVE-2025-9942HIGH8.8A vulnerability has been found in CodeAstro Real Estate Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-9941HIGH8.8A flaw has been found in CodeAstro Real Estate Management System 1.0. This impacts an unknown function of the file /regi...
CVE-2025-9940MEDIUM5.4A vulnerability was detected in CodeAstro Real Estate Management System 1.0. This affects an unknown function of the fil...
CVE-2025-9939MEDIUM5.4A security vulnerability has been detected in CodeAstro Real Estate Management System 1.0. The impacted element is an un...
CVE-2025-9938HIGH8.8A weakness has been identified in D-Link DI-8400 16.07.26A1. The affected element is the function yyxz_dlink_asp of the ...
CVE-2025-9937MEDIUM5.4A security flaw has been discovered in elunez eladmin 1.1. Impacted is the function deleteFile of the component LocalSto...
CVE-2025-9936MEDIUM4.3A vulnerability was identified in fuyang_lipengjun platform 1.0.0. This issue affects the function AdController of the f...
CVE-2025-9935CRITICAL9.8A vulnerability was determined in TOTOLINK N600R 4.3.0cu.7866_B20220506. This vulnerability affects the function sub_415...
CVE-2025-9934CRITICAL9.8A vulnerability was found in TOTOLINK X5000R 9.1.0cu.2415_B20250515. This affects the function sub_410C34 of the file /c...
CVE-2025-9933CRITICAL9.8A vulnerability has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this issue is some unknow...
CVE-2025-9932CRITICAL9.8A flaw has been found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unknown f...
CVE-2025-9931MEDIUM6.1A vulnerability was detected in Jinher OA 1.0. Affected is an unknown function of the file /jc6/platform/sys/login!chang...
CVE-2025-9930CRITICAL9.8A security vulnerability has been detected in 1000projects Beauty Parlour Management System 1.0. This impacts an unknown...
CVE-2025-9929MEDIUM4.8A weakness has been identified in code-projects Responsive Blog Site 1.0. This affects an unknown function of the file b...
CVE-2025-9616MEDIUM5.3The PopAd plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. ...
CVE-2025-9519HIGH7.2The Easy Timer plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.2.1 v...
CVE-2025-9518HIGH7.2The atec Debug plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation on...
CVE-2025-9517HIGH7.2The atec Debug plugin for WordPress is vulnerable to remote code execution in all versions up to, and including, 1.2.22 ...
CVE-2025-9516MEDIUM4.9The atec Debug plugin for WordPress is vulnerable to arbitrary file read in all versions up to, and including, 1.2.22 vi...
CVE-2025-9467MEDIUM5.3When the Vaadin Upload's start listener is used to validate metadata about an incoming upload, it is possible to bypass ...
CVE-2025-6984HIGH7.5The langchain-ai/langchain project, specifically the EverNoteLoader component, is vulnerable to XML External Entity (XXE...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now