2025 CVE Vulnerabilities

45,255 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-8953CRITICAL9.8A vulnerability was determined in SourceCodester COVID 19 Testing Management System 1.0. Affected by this issue is some ...
CVE-2025-8952CRITICAL9.8A vulnerability was found in Campcodes Online Flight Booking Management System 1.0. Affected by this vulnerability is an...
CVE-2025-5998MEDIUM6.5The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a passwor...
CVE-2025-54472HIGH7.5Unlimited memory allocation in redis protocol parser in Apache bRPC (all versions < 1.14.1) on all platforms allows atta...
CVE-2025-48862HIGH7.1Ambiguous wording in the web interface of the ctrlX OS setup mechanism could lead the user to believe that the backup fi...
CVE-2025-48861MEDIUM5.3A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to a...
CVE-2025-48860HIGH8A vulnerability in the web application of the ctrlX OS setup mechanism facilitated an authenticated (low privileged) att...
CVE-2025-8951CRITICAL9.8A vulnerability has been found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of t...
CVE-2025-8950CRITICAL9.8A vulnerability was identified in Campcodes Online Recruitment Management System 1.0. This issue affects some unknown pr...
CVE-2025-27388HIGH8.3Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user to...
CVE-2025-8949CRITICAL9.8A vulnerability was identified in D-Link DIR-825 2.10. Affected by this vulnerability is the function get_ping_app_stat ...
CVE-2025-8948CRITICAL9.8A vulnerability was determined in projectworlds Visitor Management System 1.0. Affected is an unknown function of the fi...
CVE-2025-8947CRITICAL9.8A vulnerability was found in projectworlds Visitor Management System 1.0. This issue affects some unknown processing of ...
CVE-2025-8946CRITICAL9.8A vulnerability has been found in projectworlds Online Notes Sharing Platform 1.0. This vulnerability affects unknown co...
CVE-2025-8940HIGH8.8A vulnerability was identified in Tenda AC20 up to 16.03.08.12. Affected by this vulnerability is the function strcpy of...
CVE-2025-8939HIGH8.8A vulnerability was determined in Tenda AC20 up to 16.03.08.12. Affected is an unknown function of the file /goform/Wifi...
CVE-2025-8046MEDIUM6.1The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputtin...
CVE-2025-7808MEDIUM6.1The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p...
CVE-2025-6790MEDIUM4.3The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its set...
CVE-2025-3414MEDIUM5.4The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block opti...
CVE-2025-8938MEDIUM6.3A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boa...
CVE-2025-8937HIGH8.8A vulnerability has been found in TOTOLINK N350R 1.2.3-B20130826. This vulnerability affects unknown code of the file /b...
CVE-2025-8936CRITICAL9.8A vulnerability was determined in 1000 Projects Sales Management System 1.0. Affected by this issue is some unknown func...
CVE-2025-5942MEDIUM5.7Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex...
CVE-2025-5941LOW2Netskope is notified about a potential gap in its agent (NS Client) in which a malicious actor could trigger a memory le...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now