2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-57763MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Reflected Cross-Site Scripting (XSS) vuln...
CVE-2025-57762MEDIUM6.1WeGIA is a Web manager for charitable institutions. Prior to 3.4.7, there is a Stored Cross-Site Scripting (XSS) vulnera...
CVE-2025-57761HIGH8.8WeGIA is a Web manager for charitable institutions. Prior to 3.4.10, there is a SQL Injection vulnerability in the /html...
CVE-2025-57755HIGH8.1claude-code-router is a powerful tool to route Claude Code requests to different models and customize any request. Due t...
CVE-2025-57754CRITICAL9.8eslint-ban-moment is an Eslint plugin for final assignment in VIHU. In 3.0.0 and earlier, a sensitive Supabase URI is ex...
CVE-2025-55522MEDIUM6.5Cross-site scripting (XSS) vulnerability in the component /common/reports of Akaunting v3.1.18 allows attackers to execu...
CVE-2025-55521MEDIUM6.5An issue in the component /settings/localisation of Akaunting v3.1.18 allows authenticated attackers to cause a Denial o...
CVE-2025-43756MEDIUM5.4<!--td {border: 1px solid #cccccc;}br {mso-data-placement:same-cell;}-->A reflected cross-site scripting (XSS) vulnerabi...
CVE-2025-43755MEDIUM5.4A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 t through 7.4.3.132, and Liferay DXP 2025.Q2.0, ...
CVE-2025-9308MEDIUM5.5A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/...
CVE-2025-9307CRITICAL9.8A flaw has been found in PHPGurukul Online Course Registration 3.1. This affects an unknown function of the file /admin/...
CVE-2025-9306MEDIUM5.4A vulnerability was detected in SourceCodester Advanced School Management System 1.0. The impacted element is an unknown...
CVE-2025-9162MEDIUM4.9A flaw was found in org.keycloak/keycloak-model-storage-service. The KeycloakRealmImport custom resource substitutes pla...
CVE-2025-57753MEDIUM6vite-plugin-static-copy is rollup-plugin-copy for Vite with dev server support. Files not included in src are accessible...
CVE-2025-55744MEDIUM4.3UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, some ...
CVE-2025-55743HIGH8.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the i...
CVE-2025-55742MEDIUM4.8UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, UnoPi...
CVE-2025-55420HIGH8.8A Reflected Cross Site Scripting (XSS) vulnerability was found in /index.php in FoxCMS v1.2.6. When a crafted script is ...
CVE-2025-52395CRITICAL9.8An issue in Roadcute API v.1 allows a remote attacker to execute arbitrary code via the application exposing a password ...
CVE-2025-9305CRITICAL9.8A security vulnerability has been detected in SourceCodester Online Bank Management System 1.0. The affected element is ...
CVE-2025-9304CRITICAL9.8A weakness has been identified in SourceCodester Online Bank Management System 1.0. Impacted is an unknown function of t...
CVE-2025-9303CRITICAL9.8A security flaw has been discovered in TOTOLINK A720R 4.1.5cu.630_B20250509. This issue affects the function setParental...
CVE-2025-55383HIGH8.6Moss before v0.15 has a file upload vulnerability. The "upload" function configuration allows attackers to upload files ...
CVE-2025-55371MEDIUM5.3Incorrect access control in the component /controller/PersonController.java of jshERP v3.5 allows unauthorized attackers...
CVE-2025-55297HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. The BluFi example bundled in ESP-IDF was vulner...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now