2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54347 | CRITICAL | 9.9 | 0.6% | Nov 24, 2025 | A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6... |
| CVE-2025-63958 | CRITICAL | 9.8 | 0.5% | Nov 24, 2025 | MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is acc... |
| CVE-2025-12977 | CRITICAL | 9.1 | 0.6% | Nov 24, 2025 | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with netw... |
| CVE-2025-40212 | CRITICAL | 9.8 | 0.2% | Nov 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nf... |
| CVE-2025-13585 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of th... |
| CVE-2025-13583 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /... |
| CVE-2025-13582 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functiona... |
| CVE-2025-13578 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.... |
| CVE-2025-13572 | CRITICAL | 9.8 | 0.4% | Nov 23, 2025 | A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of ... |
| CVE-2025-13565 | CRITICAL | 9.1 | 0.4% | Nov 23, 2025 | A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown fun... |
| CVE-2025-13562 | CRITICAL | 9.8 | 5.6% | Nov 23, 2025 | A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi.... |
| CVE-2025-13561 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the... |
| CVE-2025-13560 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/res... |
| CVE-2025-13557 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functional... |
| CVE-2025-13556 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality... |
| CVE-2025-13555 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file... |
| CVE-2025-13554 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function... |
| CVE-2025-13546 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t... |
| CVE-2025-13544 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is... |
| CVE-2025-65108 | CRITICAL | 10 | 0.9% | Nov 21, 2025 | md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, ... |
| CVE-2025-64767 | CRITICAL | 9.1 | 0.2% | Nov 21, 2025 | hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, th... |
| CVE-2025-62608 | CRITICAL | 9.1 | 0.5% | Nov 21, 2025 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflo... |
| CVE-2025-30201 | CRITICAL | 9.1 | 0.7% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a... |
| CVE-2025-41115 | CRITICAL | 9.8 | 17.3% | Nov 21, 2025 | SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage us... |
| CVE-2025-13357 | CRITICAL | 9.8 | 0.5% | Nov 21, 2025 | Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by def... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now