2025 CVE Vulnerabilities

45,321 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-58402HIGH7.5The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks....
CVE-2025-30062MEDIUM6.9In the "CheckUnitCodeAndKey.pl" service, the "validateOrgUnit" function is vulnerable to SQL injection.
CVE-2025-30044CRITICAL9.4In the endpoints "/cgi-bin/CliniNET.prd/utils/usrlogstat_simple.pl", "/cgi-bin/CliniNET.prd/utils/usrlogstat.pl", "/cgi-...
CVE-2025-30042HIGH7.8The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client d...
CVE-2025-30035CRITICAL9The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user ...
CVE-2025-10350HIGH8.8SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attack...
CVE-2025-15597MEDIUM6.3A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps...
CVE-2025-13673HIGH7.5The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to SQL Injection via the 'coupon...
CVE-2025-69437HIGH8.7PublicCMS v5.202506.d and earlier is vulnerable to stored XSS. Uploaded PDFs can contain JavaScript payloads and bypass ...
CVE-2025-15498CRITICAL9.3Pro3W CMS if vulnerable to SQL injection attacks. Improper neutralization of input provided into a login form allows an ...
CVE-2025-10990HIGH7.5A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processin...
CVE-2025-11950MEDIUM6.1Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in KNOWHY Adva...
CVE-2025-11252CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Signum Technology ...
CVE-2025-11251CRITICAL9.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Dayneks Software I...
CVE-2025-14142MEDIUM6.4The Electric Enquiries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'button' parameter of t...
CVE-2025-12150LOW3.1A flaw was found in Keycloak’s WebAuthn registration component. This vulnerability allows an attacker to bypass the conf...
CVE-2025-9909MEDIUM6.7A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows ...
CVE-2025-9908MEDIUM6.7A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerabilit...
CVE-2025-9907MEDIUM6.7A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerabi...
CVE-2025-9572MEDIUM6.5n authorization flaw in Foreman's GraphQL API allows low-privileged users to access metadata beyond their assigned permi...
CVE-2025-13327MEDIUM6.3A flaw was found in uv. This vulnerability allows an attacker to execute malicious code during package resolution or ins...
CVE-2025-15567LOW3.3Insufficient protection mechanisms in the Health Module may lead to partial information disclosure.
CVE-2025-15509MEDIUM4.3The SmartRemote module has insufficient restrictions on loading URLs, which may lead to some information leakage.
CVE-2025-14149MEDIUM6.4The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the p...
CVE-2025-14040MEDIUM6.4The Automotive Car Dealership Business WordPress Theme for WordPress is vulnerable to Stored Cross-Site Scripting via th...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now