2025 CVE Vulnerabilities

45,144 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-12812MEDIUM5.3Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Delinea Inc. Cloud Suite and Pri...
CVE-2025-12811MEDIUM6.9Improper Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') in Delinea Inc. Cloud Suite and Privile...
CVE-2025-8860LOW3.3A flaw was found in QEMU in the uefi-vars virtual device. When the guest writes to register UEFI_VARS_REG_BUFFER_SIZE, t...
CVE-2025-1272HIGH7.7The Linux Kernel lockdown mode for kernel versions starting on 6.12 and above for Fedora Linux has the lockdown mode dis...
CVE-2025-14876MEDIUM5.5A flaw was found in the virtio-crypto device of QEMU. A malicious guest operating system can exploit a missing length li...
CVE-2025-12343MEDIUM5.5A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in...
CVE-2025-10256MEDIUM5.5A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a...
CVE-2025-0577MEDIUM4.8An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return pr...
CVE-2025-70064HIGH8.8PHPGurukul Hospital Management System v4.0 contains a Privilege Escalation vulnerability. A low-privileged user (Patient...
CVE-2025-70063MEDIUM6.5The 'Medical History' module in PHPGurukul Hospital Management System v4.0 contains an Insecure Direct Object Reference ...
CVE-2025-70062MEDIUM6.5PHPGurukul Hospital Management System v4.0 contains a Cross-Site Request Forgery (CSRF) vulnerability in the 'Add Doctor...
CVE-2025-69287MEDIUM5.4The BSV Blockchain SDK is a unified TypeScript SDK for developing scalable apps on the BSV Blockchain. Prior to version ...
CVE-2025-70152CRITICAL9.8code-projects Community Project Scholars Tracking System 1.0 is vulnerable to SQL Injection in the admin user management...
CVE-2025-70151HIGH8.8code-projects Scholars Tracking System 1.0 allows an authenticated attacker to achieve remote code execution via unrestr...
CVE-2025-70150CRITICAL9.8CodeAstro Membership Management System 1.0 contains a missing authentication vulnerability in delete_members.php that al...
CVE-2025-70148HIGH7.5Missing authentication and authorization in print_membership_card.php in CodeAstro Membership Management System 1.0 allo...
CVE-2025-14009CRITICAL10A critical vulnerability exists in the NLTK downloader component of nltk/nltk, affecting all versions. The _unzip_iter f...
CVE-2025-70149CRITICAL9.8CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in print_membership_card.php via the ID parame...
CVE-2025-70147HIGH7.5Missing authentication in /admin/student.php and /admin/teacher.php in ProjectWorlds Online Time Table Generator 1.0 all...
CVE-2025-70146CRITICAL9.1Missing authentication in multiple administrative action scripts under /admin/ in ProjectWorlds Online Time Table Genera...
CVE-2025-70141CRITICAL9.4SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX disp...
CVE-2025-13965Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a ...
CVE-2025-13933Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12500. Reason: This candidate is a ...
CVE-2025-13602Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2025-71237MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nilfs2: Fix potential block overflow that cause sys...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now