2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-9239MEDIUM6.3A vulnerability was identified in elunez eladmin up to 2.7. Affected by this vulnerability is the function EncryptUtils ...
CVE-2025-9238HIGH7.3A vulnerability was determined in Swatadru Exam-Seating-Arrangement up to 97335ccebf95468d92525f4255a2241d2b0b002f. Affe...
CVE-2025-9237MEDIUM5.4A vulnerability was found in CodeAstro Ecommerce Website 1.0. This impacts an unknown function of the file /customer/my_...
CVE-2025-9236HIGH8.8A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown function of the file /intranet...
CVE-2025-55746HIGH7.5Directus is a real-time API and App dashboard for managing SQL database content. From 10.8.0 to before 11.9.3, a vulnera...
CVE-2025-47054MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...
CVE-2025-9235MEDIUM5.4A flaw has been found in Scada-LTS up to 2.7.8.1. The impacted element is an unknown function of the file compound_event...
CVE-2025-9234MEDIUM5.4A vulnerability was detected in Scada-LTS up to 2.7.8.1. The affected element is an unknown function of the file mainten...
CVE-2025-8612HIGH7.3AOMEI Backupper Workstation Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local att...
CVE-2025-8611CRITICAL9.8AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-8610CRITICAL9.8AOMEI Cyber Backup Missing Authentication for Critical Function Remote Code Execution Vulnerability. This vulnerability ...
CVE-2025-8415MEDIUM5.9A vulnerability was found in the Cryostat HTTP API. Cryostat's HTTP API binds to all network interfaces, allowing possib...
CVE-2025-8309HIGH8.1There is an improper privilege management vulnerability identified in ManageEngine's Asset Explorer, ServiceDesk Plus, S...
CVE-2025-6183HIGH7The StrongDM macOS client incorrectly processed JSON-formatted messages. Attackers could potentially modify macOS system...
CVE-2025-6182HIGH8.5The StrongDM Windows service incorrectly handled communication related to system certificate management. Attackers could...
CVE-2025-6181HIGH8.5The StrongDM Windows service incorrectly handled input validation. Authenticated attackers could potentially exploit thi...
CVE-2025-6180HIGH8.5The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and r...
CVE-2025-55444CRITICAL9.8A SQL injection vulnerability exists in the id2 parameter of the cancel_booking.php page in Online Artwork and Fine Arts...
CVE-2025-50904CRITICAL9.8There is an authentication bypass vulnerability in WinterChenS my-site thru commit 6c79286 (2025-06-11). An attacker can...
CVE-2025-50901CRITICAL9.8JeeWMS 771e4f5d0c01ffdeae1671be4cf102b73a3fe644 (2025-05-19) contains incorrect authentication bypass vulnerability, whi...
CVE-2025-46998MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46962MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46936MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46932MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t...
CVE-2025-46856MEDIUM5.4Adobe Experience Manager versions 6.5.22 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerabilit...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now