2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-13555CRITICAL9.8A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file...
CVE-2025-13554CRITICAL9.8A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function...
CVE-2025-13546CRITICAL9.8A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t...
CVE-2025-13544CRITICAL9.8A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is...
CVE-2025-65108CRITICAL10md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, ...
CVE-2025-64767CRITICAL9.1hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, th...
CVE-2025-62608CRITICAL9.1MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflo...
CVE-2025-30201CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a...
CVE-2025-41115CRITICAL9.8SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage us...
CVE-2025-13357CRITICAL9.8Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by def...
CVE-2025-11127CRITICAL9.8The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly ve...
CVE-2025-11456CRITICAL9.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2025-64310CRITICAL9.8EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp...
CVE-2025-64762CRITICAL9.1The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut...
CVE-2025-64755CRITICAL9.8Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible ...
CVE-2025-13485CRITICAL9.8A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p...
CVE-2025-64655CRITICAL9.8Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile...
CVE-2025-62207CRITICAL9.8Azure Monitor Elevation of Privilege Vulnerability
CVE-2025-59245CRITICAL9.8Microsoft SharePoint Online Elevation of Privilege Vulnerability
CVE-2025-49752CRITICAL10Azure Bastion Elevation of Privilege Vulnerability
CVE-2025-63807CRITICAL9.8An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (...
CVE-2025-63685CRITICAL9.8Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of syste...
CVE-2025-10571CRITICAL9.6Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB...
CVE-2025-63888CRITICAL9.8The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code exec...
CVE-2025-64428CRITICAL9.8Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection....

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now