CVEs from 2025

8,928 normalized CVEs published or assigned in this year.

Total
8,928
critical
critical 1,361
high
high 2,043
medium
medium 2,040
low
low 204
% Critical
15.2%
% with KEV
2.0%
% with exploit
2.8%

Top products

  • i-educar 80
  • office_long_term_servicing_channel 35
  • office 34
  • best_salon_management_system 33
  • apartment_management_system 30
  • gcp 29
  • inventory_management_system 28
  • online_learning_management_system 21
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2025-7100 critical 9.8 9.8 11mo ago A vulnerability was found in BoyunCMS up to 1.4.20 and classified as critical. Affected by this issue is some unknown functionality of the file /application/user/controller/Index.php. The manipulatio…
CVE-2025-28983 critical 9.8 9.8 11mo ago Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Click & Pledge Connect allows Privilege Escalation. This issue affects Click & Ple…
CVE-2025-6963 critical 9.8 9.8 11mo ago A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /myprofile.php. The manipulation of the argu…
CVE-2025-6962 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, was found in Campcodes Employee Management System 1.0. This affects an unknown part of the file /myprofileup.php. The manipulation of the argument I…
CVE-2025-6961 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, has been found in Campcodes Employee Management System 1.0. Affected by this issue is some unknown functionality of the file /mark.php. The manipula…
CVE-2025-6960 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in Campcodes Employee Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /empproject.php. The manipulation …
CVE-2025-6959 critical 9.8 9.8 11mo ago A vulnerability classified as critical has been found in Campcodes Employee Management System 1.0. Affected is an unknown function of the file /eloginwel.php. The manipulation of the argument ID lead…
CVE-2025-6958 critical 9.8 9.8 11mo ago A vulnerability was found in Campcodes Employee Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /edit.php. The manipulation of the argumen…
CVE-2025-6957 critical 9.8 9.8 11mo ago A vulnerability was found in Campcodes Employee Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /process/eprocess.php. The manipulation of…
CVE-2025-6956 critical 9.8 9.8 11mo ago A vulnerability was found in Campcodes Employee Management System 1.0. It has been classified as critical. This affects an unknown part of the file /changepassemp.php. The manipulation of the argumen…
CVE-2025-6955 critical 9.8 9.8 11mo ago A vulnerability was found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /process/aprocess.php. The manipulat…
CVE-2025-6954 critical 9.8 9.8 11mo ago A vulnerability has been found in Campcodes Employee Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /applyleave.php. The mani…
CVE-2025-6938 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /editcus.php. The manipulation of th…
CVE-2025-6937 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /large.php. The manipulation of the …
CVE-2025-6936 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Simple Pizza Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /addpro.php. The manipulation of the argument…
CVE-2025-6935 critical 9.8 9.8 11mo ago A vulnerability was found in Campcodes Sales and Inventory System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pages/payment_add.php. The manipula…
CVE-2025-6917 critical 9.8 9.8 11mo ago A vulnerability has been found in code-projects Online Hotel Booking 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/registration.php. The manipulation of t…
CVE-2025-6907 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in code-projects Car Rental System 1.0. This vulnerability affects unknown code of the file /book_car.php. The manipulation of the argument fname lead…
CVE-2025-6906 critical 9.8 9.8 11mo ago A vulnerability classified as critical has been found in code-projects Car Rental System 1.0. This affects an unknown part of the file /login.php. The manipulation of the argument uname leads to sql …
CVE-2025-6905 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, has been found in code-projects Car Rental System 1.0. This issue affects some unknown processing of the file /signup.php. The manipulation of the a…
CVE-2025-6904 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_cars.php. The manipulation…
CVE-2025-6903 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Car Rental System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The mani…
CVE-2025-6902 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /php_action/editUser.php. The manipulation …
CVE-2025-6901 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/removeUser.php. The manipulat…
CVE-2025-6900 critical 9.8 9.8 11mo ago A vulnerability has been found in code-projects Library System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-book.php. The manipulation of the argument imag…
CVE-2025-6897 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in D-Link DI-7300G+ 19.12.25A1. Affected by this vulnerability is an unknown functionality of the file httpd_debug.asp. The manipulation of the argume…
CVE-2025-6891 critical 9.8 9.8 11mo ago A vulnerability classified as critical has been found in code-projects Inventory Management System 1.0. Affected is an unknown function of the file /php_action/createUser.php. The manipulation of the…
CVE-2025-6889 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Movie Ticketing System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /logIn.php. The manipulation of the argume…
CVE-2025-6888 critical 9.8 9.8 11mo ago A vulnerability was found in PHPGurukul Teachers Record Management System 2.1. It has been classified as critical. This affects an unknown part of the file /admin/changeimage.php. The manipulation of…
CVE-2025-6885 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, was found in PHPGurukul Teachers Record Management System 2.1. Affected is an unknown function of the file /admin/edit-teacher-detail.php. The manip…
CVE-2025-6871 critical 9.8 9.8 11mo ago A vulnerability classified as critical has been found in SourceCodester Simple Company Website 1.0. This affects an unknown part of the file /classes/Login.php. The manipulation of the argument Usern…
CVE-2025-6863 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in PHPGurukul Local Services Search Engine Management System 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/edit-c…
CVE-2025-6853 critical 9.8 9.8 11mo ago Langchain-Chatchat has a Path Traversal vulnerability
CVE-2025-6847 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in code-projects Simple Forum 1.0. This vulnerability affects unknown code of the file /forum_edit.php. The manipulation of the argument iii leads to …
CVE-2025-6845 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Simple Forum 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /register1.php. The manipulation of the ar…
CVE-2025-6844 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Simple Forum 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /signin.php. The manipulation of …
CVE-2025-6843 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Simple Photo Gallery 1.0. It has been classified as critical. Affected is an unknown function of the file /upload-photo.php. The manipulation of the argumen…
CVE-2025-6840 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, was found in code-projects Product Inventory System 1.0. This affects an unknown part of the file /index.php of the component Login. The manipulatio…
CVE-2025-6837 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in code-projects Library System 1.0. Affected by this vulnerability is an unknown functionality of the file /profile.php. The manipulation of the argu…
CVE-2025-6836 critical 9.8 9.8 11mo ago A vulnerability classified as critical has been found in code-projects Library System 1.0. Affected is an unknown function of the file /profile.php. The manipulation of the argument phone leads to sq…
CVE-2025-6835 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Library System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /student-issue-book.php. The manipulation of the a…
CVE-2025-6834 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/editPayment.php. The mani…
CVE-2025-6828 critical 9.8 9.8 11mo ago A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /orders.php. The manipulation of the ar…
CVE-2025-6827 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/editOrder.php. The manipulation lea…
CVE-2025-6826 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, has been found in code-projects Payroll Management System 1.0. Affected by this issue is some unknown functionality of the file /Payroll_Management_…
CVE-2025-6823 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/editProduct.php. The mani…
CVE-2025-6822 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/removeProduct.php. The ma…
CVE-2025-6821 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /php_action/createOrder.php. The manipulation …
CVE-2025-6820 critical 9.8 9.8 11mo ago A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /php_action/createProduct.php. …
CVE-2025-6819 critical 9.8 9.8 11mo ago A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /php_action/removeBr…
CVE-2025-6777 critical 9.8 9.8 11mo ago A vulnerability, which was classified as critical, has been found in code-projects Food Distributor Site 1.0. This issue affects some unknown processing of the file /admin/process_login.php. The mani…
CVE-2025-6776 critical 9.8 9.8 11mo ago A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the compo…
CVE-2025-6775 critical 9.8 9.8 11mo ago A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the component User Creat…
CVE-2025-6668 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been classified as critical. This affects an unknown part of the file /php_action/fetchSelectedBrand.php. The manipu…
CVE-2025-6665 critical 9.8 9.8 1y ago A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /php_action/editBran…
CVE-2025-6621 critical 9.8 9.8 1y ago A vulnerability classified as critical has been found in TOTOLINK CA300-PoE 6.2c.884. This affects the function QuickSetting of the file ap.so. The manipulation of the argument hour/minute leads to o…
CVE-2025-6620 critical 9.8 9.8 1y ago A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been rated as critical. Affected by this issue is the function setUpgradeUboot of the file upgrade.so. The manipulation of the argumen…
CVE-2025-6619 critical 9.8 9.8 1y ago A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been declared as critical. Affected by this vulnerability is the function setUpgradeFW of the file upgrade.so. The manipulation of the…
CVE-2025-6618 critical 9.8 9.8 1y ago A vulnerability was found in TOTOLINK CA300-PoE 6.2c.884. It has been classified as critical. Affected is the function SetWLanApcliSettings of the file wps.so. The manipulation of the argument PIN le…
CVE-2025-6612 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /php_action/removeCategories.php. The…
CVE-2025-6611 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Inventory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /php_action/createBrand.php. The mani…
CVE-2025-6580 critical 9.8 9.8 1y ago A vulnerability classified as critical has been found in SourceCodester Best Salon Management System 1.0. Affected is an unknown function of the component Login. The manipulation of the argument User…
CVE-2025-6579 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Car Rental System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /message_admin.php. The manipulation of the arg…
CVE-2025-6578 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_account.php.…
CVE-2025-6567 critical 9.8 9.8 1y ago A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file Recruitment/admin/view_applicati…
CVE-2025-6517 critical 9.8 9.8 1y ago A vulnerability was found in Dromara MaxKey up to 4.1.7 and classified as critical. This issue affects the function Add of the file maxkey-webs\maxkey-web-mgt\src\main\java\org\dromara\maxkey\web\app…
CVE-2025-6503 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Inventory Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /php_action/fetchSelectedCategories.php. …
CVE-2025-6502 critical 9.8 9.8 1y ago A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /php_action/changePassword.php. The man…
CVE-2025-6501 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, was found in code-projects Inventory Management System 1.0. This affects an unknown part of the file /php_action/createCategories.php. The manipulat…
CVE-2025-6500 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, has been found in code-projects Inventory Management System 1.0. Affected by this issue is some unknown functionality of the file /php_action/editCa…
CVE-2025-6489 critical 9.8 9.8 1y ago A vulnerability has been found in itsourcecode Agri-Trading Online Shopping System 1.0 and classified as critical. This vulnerability affects unknown code of the file /transactionsave.php. The manipu…
CVE-2025-6483 critical 9.8 9.8 1y ago A vulnerability has been found in code-projects Simple Pizza Ordering System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /edituser.php. The …
CVE-2025-6482 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, was found in code-projects Simple Pizza Ordering System 1.0. Affected is an unknown function of the file /edituser-exec.php. The manipulation of the…
CVE-2025-6481 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, has been found in code-projects Simple Pizza Ordering System 1.0. This issue affects some unknown processing of the file /update.php. The manipulati…
CVE-2025-6480 critical 9.8 9.8 1y ago A vulnerability classified as critical was found in code-projects Simple Pizza Ordering System 1.0. This vulnerability affects unknown code of the file /addcatexec.php. The manipulation of the argume…
CVE-2025-6479 critical 9.8 9.8 1y ago A vulnerability classified as critical has been found in code-projects Simple Pizza Ordering System 1.0. This affects an unknown part of the file /salesreport.php. The manipulation of the argument da…
CVE-2025-6474 critical 9.8 9.8 1y ago A vulnerability has been found in code-projects Inventory Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /changeUsername.php. The manipulation o…
CVE-2025-6472 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, has been found in code-projects Online Bidding System 1.0. Affected by this issue is some unknown functionality of the file /showprod.php. The manip…
CVE-2025-6471 critical 9.8 9.8 1y ago A vulnerability classified as critical was found in code-projects Online Bidding System 1.0. Affected by this vulnerability is an unknown functionality of the file /administrator. The manipulation of…
CVE-2025-6470 critical 9.8 9.8 1y ago A vulnerability classified as critical has been found in code-projects Online Bidding System 1.0. Affected is an unknown function of the file /bidlog.php. The manipulation of the argument ID leads to…
CVE-2025-6469 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Online Bidding System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the argum…
CVE-2025-6468 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Online Bidding System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /bidnow.php. The manipulation of the argume…
CVE-2025-6467 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Online Bidding System 1.0. It has been classified as critical. This affects an unknown part of the file /login.php. The manipulation of the argument User le…
CVE-2025-6466 critical 9.8 9.8 1y ago A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/upload of the file ruoyi-modules/ruoyi-system/src/m…
CVE-2025-6458 critical 9.8 9.8 1y ago A vulnerability has been found in code-projects Online Hotel Reservation System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/execedituser.php. The manipu…
CVE-2025-6457 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, was found in code-projects Online Hotel Reservation System 1.0. This affects an unknown part of the file /reservation/demo.php. The manipulation of …
CVE-2025-6456 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, has been found in code-projects Online Hotel Reservation System 1.0. Affected by this issue is some unknown functionality of the file /reservation/o…
CVE-2025-6455 critical 9.8 9.8 1y ago A vulnerability classified as critical was found in code-projects Online Hotel Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the file /messageexec.php. The man…
CVE-2025-6451 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/delete_pending.php.…
CVE-2025-6450 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/confirm_reserve.php. The man…
CVE-2025-6449 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/checkout_quer…
CVE-2025-6448 critical 9.8 9.8 1y ago A vulnerability has been found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/de…
CVE-2025-6447 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, was found in code-projects Simple Online Hotel Reservation System 1.0. Affected is an unknown function of the file /admin/index.php. The manipulatio…
CVE-2025-6446 critical 9.8 9.8 1y ago A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. This issue affects some unknown processing of the file /clientdetails/admin/index.php. Th…
CVE-2025-6421 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/add_account.php. Th…
CVE-2025-6420 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/add_room.php. The m…
CVE-2025-6419 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/edit_room.php. The manipulat…
CVE-2025-6418 critical 9.8 9.8 1y ago A vulnerability was found in code-projects Simple Online Hotel Reservation System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/edit_query_ac…
CVE-2025-6409 critical 9.8 9.8 1y ago A vulnerability was found in PHPGurukul Art Gallery Management System 1.1 and classified as critical. This issue affects some unknown processing of the file /admin/forgot-password.php. The manipulati…
CVE-2025-6408 critical 9.8 9.8 1y ago A vulnerability has been found in Campcodes Online Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /doctor/search.php. The manipulation …