2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-71248Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71247Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71246Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71245Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2025-71244MEDIUM6.1SPIP before 4.4.5 and 4.3.9 allows an Open Redirect via the login form when used in AJAX mode. An attacker can craft a m...
CVE-2025-71243CRITICAL9.8The 'Saisies pour formulaire' (Saisies) plugin for SPIP versions 5.4.0 through 5.11.0 contains a critical Remote Code Ex...
CVE-2025-71242MEDIUM6.5SPIP before 4.3.6, 4.2.17, and 4.1.20 allows unauthorized content disclosure in the private area. The application does n...
CVE-2025-71241MEDIUM6.1SPIP before 4.3.6, 4.2.17, and 4.1.20 allows Cross-Site Scripting (XSS) in the private area. The content of the error me...
CVE-2025-71240MEDIUM5.4SPIP before 4.2.15 allows Cross-Site Scripting (XSS) via crafted content in HTML code tags. The application does not pro...
CVE-2025-55853CRITICAL9.1SoftVision webPDF before 10.0.2 is vulnerable to Server-Side Request Forgery (SSRF). The PDF converter function does not...
CVE-2025-9953CRITICAL9.8Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in DATABASE Software Training Consulting Ltd....
CVE-2025-8350CRITICAL9.8Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Intern...
CVE-2025-9062HIGH7.3Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envan...
CVE-2025-15563MEDIUM5.3Any unauthenticated user can reset the WorkTime on-prem database configuration by sending a specific HTTP request to the...
CVE-2025-15562MEDIUM6.1The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper enco...
CVE-2025-15561HIGH7.8An attacker can exploit the update behavior of the WorkTime monitoring daemon to elevate privileges on the local system ...
CVE-2025-15560HIGH8.8An authenticated attacker with minimal permissions can exploit a SQL injection in the WorkTime server "widget" API endpo...
CVE-2025-15559CRITICAL9.8An unauthenticated attacker can inject OS commands when calling a server API endpoint in NesterSoft WorkTime. The server...
CVE-2025-13590HIGH7.2A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the d...
CVE-2025-12107HIGH7.2Due to the use of a vulnerable third-party Velocity template engine, a malicious actor with admin privilege may inject a...
CVE-2025-41023MEDIUM6.9An authentication bypass vulnerability has been found in Thesamur's AutoGPT. This vulnerability allows an attacker to by...
CVE-2025-40697MEDIUM5.1Reflected Cross-Site Scripting (XSS) vulnerability in '/index.php' in Lewe WebMeasure, which allows remote attackers to ...
CVE-2025-4960HIGH7.8The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege esca...
CVE-2025-4521HIGH8.8The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala...
CVE-2025-15586CRITICAL10OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw whic...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now