2025 CVE Vulnerabilities

45,172 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-65572MEDIUM6.1Cross Site Scripting (XSS) vulnerability in AllskyTeam AllSky v2024.12.06_06 allows remote attackers to execute arbitrar...
CVE-2025-65300MEDIUM5.4A stored Cross-Site Scripting (XSS) vulnerability exists in the Coohom SaaS Platform feVersion=1760060603897 (2025-10-28...
CVE-2025-14336CRITICAL9.8A vulnerability was found in itsourcecode Student Management System 1.0. Affected by this issue is some unknown function...
CVE-2025-14335CRITICAL9.8A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unkno...
CVE-2025-14334CRITICAL9.8A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /new_ad...
CVE-2025-11531HIGH8.8HP System Event Utility and Omen Gaming Hub might allow execution of certain files outside of their restricted paths. T...
CVE-2025-65594HIGH8.1OpenSIS 9.2 and below is vulnerable to Incorrect Access Control in Student.php, which allows an authenticated low-privil...
CVE-2025-64894MEDIUM5.5DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could lead to ap...
CVE-2025-64893HIGH7.1DNG SDK versions 1.7.0 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory exposur...
CVE-2025-64784HIGH7.1DNG SDK versions 1.7.0 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory ...
CVE-2025-64783HIGH7.8DNG SDK versions 1.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in ...
CVE-2025-64680HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-64679HIGH7.8Heap-based buffer overflow in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
CVE-2025-64678HIGH8.8Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execut...
CVE-2025-64673HIGH7.8Improper access control in Storvsp.sys Driver allows an authorized attacker to elevate privileges locally.
CVE-2025-64672CRITICAL9Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo...
CVE-2025-64671HIGH7.8Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-64670MEDIUM6.5Exposure of sensitive information to an unauthorized actor in Microsoft Graphics Component allows an authorized attacker...
CVE-2025-64667MEDIUM5.3User interface (ui) misrepresentation of critical information in Microsoft Exchange Server allows an unauthorized attack...
CVE-2025-64666HIGH7.5Improper input validation in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a networ...
CVE-2025-64661HIGH7.8Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an a...
CVE-2025-64658HIGH7.5Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an a...
CVE-2025-64471HIGH7.5A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb...
CVE-2025-64447HIGH8.1A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, ...
CVE-2025-64156HIGH7.2An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiV...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now