2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-49897HIGH8.8Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Vertical ...
CVE-2025-49432MEDIUM5.3Missing Authorization vulnerability in FWDesign Ultimate Video Player fwduvp allows Exploiting Incorrectly Configured Ac...
CVE-2025-5048HIGH7.8A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force a Memory Corruption vulnerabili...
CVE-2025-5047HIGH7.8A maliciously crafted DGN file, when parsed through Autodesk AutoCAD, can force an Uninitialized Variable vulnerability....
CVE-2025-5046HIGH7.8A maliciously crafted DGN file, when linked or imported into Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerabi...
CVE-2025-55203MEDIUM5.4Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerabi...
CVE-2025-54989HIGH7.5Firebird is a relational database. Prior to versions 3.0.13, 4.0.6, and 5.0.3, there is an XDR message parsing NULL poin...
CVE-2025-54466CRITICAL9.8Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum ...
CVE-2025-24975HIGH8.8Firebird is a relational database. Prior to snapshot versions 4.0.6.3183, 5.0.2.1610, and 6.0.0.609, Firebird is vulnera...
CVE-2025-9053CRITICAL9.8A vulnerability has been found in projectworlds Travel Management System 1.0. This vulnerability affects unknown code of...
CVE-2025-9052CRITICAL9.8A vulnerability was identified in projectworlds Travel Management System 1.0. This affects an unknown part of the file /...
CVE-2025-9051CRITICAL9.8A vulnerability was determined in projectworlds Travel Management System 1.0. Affected by this issue is some unknown fun...
CVE-2025-9050CRITICAL9.8A vulnerability was found in projectworlds Travel Management System 1.0. Affected by this vulnerability is an unknown fu...
CVE-2025-54475HIGH8.7A SQL injection vulnerability in the JS Jobs plugin versions 1.3.2-1.4.4 for Joomla allows low-privilege users to execut...
CVE-2025-54474HIGH8.5A SQLi vulnerability in DJ-Classifieds component 3.9.2-3.10.1 for Joomla was discovered. The issue allows privileged use...
CVE-2025-54473CRITICAL9.2An authenticated RCE vulnerability in Phoca Commander component 1.0.0-4.0.0 and 5.0.0-5.0.1 for Joomla was discovered. T...
CVE-2025-1929HIGH7.2Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Risk Yazılım Tekno...
CVE-2025-9047CRITICAL9.8A vulnerability has been found in projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-9046HIGH8.8A vulnerability was identified in Tenda AC20 16.03.08.12. This issue affects the function sub_46A2AC of the file /goform...
CVE-2025-9028CRITICAL9.8A flaw has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of the file /a...
CVE-2025-26709MEDIUM5.7There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface...
CVE-2025-9027CRITICAL9.8A vulnerability has been found in code-projects Online Medicine Guide 1.0. This vulnerability affects unknown code of th...
CVE-2025-9026CRITICAL9.8A vulnerability was identified in D-Link DIR-860L 2.04.B04. This affects the function ssdpcgi_main of the file htdocs/cg...
CVE-2025-9025HIGH8.8A vulnerability was determined in code-projects Simple Cafe Ordering System 1.0. Affected by this issue is some unknown ...
CVE-2025-9024CRITICAL9.8A vulnerability was found in PHPGurukul Beauty Parlour Management System 1.1. Affected by this vulnerability is an unkno...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now