2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13555 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was detected in Campcodes School File Management System 1.0. Affected is an unknown function of the file... |
| CVE-2025-13554 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A security vulnerability has been detected in Campcodes Supplier Management System 1.0. This impacts an unknown function... |
| CVE-2025-13546 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A vulnerability was detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected by t... |
| CVE-2025-13544 | CRITICAL | 9.8 | 0.3% | Nov 23, 2025 | A weakness has been identified in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3. Affected is... |
| CVE-2025-65108 | CRITICAL | 10 | 0.9% | Nov 21, 2025 | md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, ... |
| CVE-2025-64767 | CRITICAL | 9.1 | 0.2% | Nov 21, 2025 | hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, th... |
| CVE-2025-62608 | CRITICAL | 9.1 | 0.5% | Nov 21, 2025 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflo... |
| CVE-2025-30201 | CRITICAL | 9.1 | 0.7% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a... |
| CVE-2025-41115 | CRITICAL | 9.8 | 17.3% | Nov 21, 2025 | SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage us... |
| CVE-2025-13357 | CRITICAL | 9.8 | 0.5% | Nov 21, 2025 | Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by def... |
| CVE-2025-11127 | CRITICAL | 9.8 | 0.3% | Nov 21, 2025 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly ve... |
| CVE-2025-11456 | CRITICAL | 9.8 | 0.6% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2025-64310 | CRITICAL | 9.8 | 0.4% | Nov 21, 2025 | EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp... |
| CVE-2025-64762 | CRITICAL | 9.1 | 0.3% | Nov 21, 2025 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut... |
| CVE-2025-64755 | CRITICAL | 9.8 | 0.4% | Nov 21, 2025 | Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible ... |
| CVE-2025-13485 | CRITICAL | 9.8 | 0.3% | Nov 21, 2025 | A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p... |
| CVE-2025-64655 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile... |
| CVE-2025-62207 | CRITICAL | 9.8 | 0.6% | Nov 20, 2025 | Azure Monitor Elevation of Privilege Vulnerability |
| CVE-2025-59245 | CRITICAL | 9.8 | 0.9% | Nov 20, 2025 | Microsoft SharePoint Online Elevation of Privilege Vulnerability |
| CVE-2025-49752 | CRITICAL | 10 | 0.9% | Nov 20, 2025 | Azure Bastion Elevation of Privilege Vulnerability |
| CVE-2025-63807 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (... |
| CVE-2025-63685 | CRITICAL | 9.8 | 0.3% | Nov 20, 2025 | Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of syste... |
| CVE-2025-10571 | CRITICAL | 9.6 | 0.3% | Nov 20, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB... |
| CVE-2025-63888 | CRITICAL | 9.8 | 0.5% | Nov 20, 2025 | The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code exec... |
| CVE-2025-64428 | CRITICAL | 9.8 | 0.5% | Nov 20, 2025 | Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now