2025 CVE Vulnerabilities

45,200 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-11368MEDIUM5.3The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all vers...
CVE-2025-64310CRITICAL9.8EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp...
CVE-2025-64762CRITICAL9.1The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut...
CVE-2025-64755CRITICAL9.8Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible ...
CVE-2025-64751HIGH8.8OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z...
CVE-2025-62426MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/c...
CVE-2025-62372MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can...
CVE-2025-62164HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor...
CVE-2025-13485CRITICAL9.8A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p...
CVE-2025-64660HIGH8Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne...
CVE-2025-64655CRITICAL9.8Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile...
CVE-2025-62459MEDIUM6.1Microsoft Defender Portal Spoofing Vulnerability
CVE-2025-62207CRITICAL9.8Azure Monitor Elevation of Privilege Vulnerability
CVE-2025-59245CRITICAL9.8Microsoft SharePoint Online Elevation of Privilege Vulnerability
CVE-2025-49752CRITICAL10Azure Bastion Elevation of Privilege Vulnerability
CVE-2025-36072HIGH8.8IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi...
CVE-2025-13484MEDIUM6.1A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe...
CVE-2025-61138HIGH7.5Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.
CVE-2025-36160HIGH7.5IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in...
CVE-2025-36159MEDIUM5.5IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their ide...
CVE-2025-36158MEDIUM5.5IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from f...
CVE-2025-36153MEDIUM6.1IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated atta...
CVE-2025-13087HIGH7.5A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code ex...
CVE-2025-64770HIGH7The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may all...
CVE-2025-63807CRITICAL9.8An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now