2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-54347CRITICAL9.9A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6...
CVE-2025-63958CRITICAL9.8MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is acc...
CVE-2025-12977CRITICAL9.1Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with netw...
CVE-2025-40212CRITICAL9.8In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nf...
CVE-2025-13585CRITICAL9.8A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of th...
CVE-2025-13583CRITICAL9.8A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /...
CVE-2025-13582CRITICAL9.8A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functiona...
CVE-2025-13578CRITICAL9.8A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index....
CVE-2025-13572CRITICAL9.8A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of ...
CVE-2025-13565CRITICAL9.1A weakness has been identified in SourceCodester Inventory Management System 1.0. The affected element is an unknown fun...
CVE-2025-13562CRITICAL9.8A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi....
CVE-2025-13561CRITICAL9.8A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the...
CVE-2025-13560CRITICAL9.8A vulnerability was found in SourceCodester Company Website CMS 1.0. This affects an unknown part of the file /admin/res...
CVE-2025-13557CRITICAL9.8A vulnerability has been found in Campcodes Online Polling System 1.0. Affected by this issue is some unknown functional...
CVE-2025-13556CRITICAL9.8A flaw has been found in Campcodes Online Polling System 1.0. Affected by this vulnerability is an unknown functionality...
CVE-2025-13555CRITICAL9.8A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file...
CVE-2025-13554CRITICAL9.8A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function...
CVE-2025-13546CRITICAL9.8A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t...
CVE-2025-13544CRITICAL9.8A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is...
CVE-2025-65108CRITICAL10md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, ...
CVE-2025-64767CRITICAL9.1hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, th...
CVE-2025-62608CRITICAL9.1MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflo...
CVE-2025-30201CRITICAL9.1Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a...
CVE-2025-41115CRITICAL9.8SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage us...
CVE-2025-13357CRITICAL9.8Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by def...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now