2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11368 | MEDIUM | 5.3 | 0.9% | Nov 21, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all vers... |
| CVE-2025-64310 | CRITICAL | 9.8 | 0.4% | Nov 21, 2025 | EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp... |
| CVE-2025-64762 | CRITICAL | 9.1 | 0.3% | Nov 21, 2025 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut... |
| CVE-2025-64755 | CRITICAL | 9.8 | 0.4% | Nov 21, 2025 | Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible ... |
| CVE-2025-64751 | HIGH | 8.8 | 0.3% | Nov 21, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2025-62426 | MEDIUM | 6.5 | 0.3% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/c... |
| CVE-2025-62372 | MEDIUM | 6.5 | 0.3% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can... |
| CVE-2025-62164 | HIGH | 8.8 | 0.8% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor... |
| CVE-2025-13485 | CRITICAL | 9.8 | 0.3% | Nov 21, 2025 | A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p... |
| CVE-2025-64660 | HIGH | 8 | 0.5% | Nov 20, 2025 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne... |
| CVE-2025-64655 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile... |
| CVE-2025-62459 | MEDIUM | 6.1 | 0.3% | Nov 20, 2025 | Microsoft Defender Portal Spoofing Vulnerability |
| CVE-2025-62207 | CRITICAL | 9.8 | 0.6% | Nov 20, 2025 | Azure Monitor Elevation of Privilege Vulnerability |
| CVE-2025-59245 | CRITICAL | 9.8 | 0.9% | Nov 20, 2025 | Microsoft SharePoint Online Elevation of Privilege Vulnerability |
| CVE-2025-49752 | CRITICAL | 10 | 0.9% | Nov 20, 2025 | Azure Bastion Elevation of Privilege Vulnerability |
| CVE-2025-36072 | HIGH | 8.8 | 0.4% | Nov 20, 2025 | IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi... |
| CVE-2025-13484 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe... |
| CVE-2025-61138 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory. |
| CVE-2025-36160 | HIGH | 7.5 | 0.2% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in... |
| CVE-2025-36159 | MEDIUM | 5.5 | 0.1% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their ide... |
| CVE-2025-36158 | MEDIUM | 5.5 | 0.1% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from f... |
| CVE-2025-36153 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated atta... |
| CVE-2025-13087 | HIGH | 7.5 | 6.3% | Nov 20, 2025 | A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code ex... |
| CVE-2025-64770 | HIGH | 7 | 0.2% | Nov 20, 2025 | The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may all... |
| CVE-2025-63807 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now