2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11127 | CRITICAL | 9.8 | 0.3% | Nov 21, 2025 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly ve... |
| CVE-2025-11456 | CRITICAL | 9.8 | 0.6% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due... |
| CVE-2025-64310 | CRITICAL | 9.8 | 0.4% | Nov 21, 2025 | EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp... |
| CVE-2025-64762 | CRITICAL | 9.1 | 0.3% | Nov 21, 2025 | The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut... |
| CVE-2025-64755 | CRITICAL | 9.8 | 0.4% | Nov 21, 2025 | Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible ... |
| CVE-2025-13485 | CRITICAL | 9.8 | 0.3% | Nov 21, 2025 | A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p... |
| CVE-2025-64655 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile... |
| CVE-2025-62207 | CRITICAL | 9.8 | 0.6% | Nov 20, 2025 | Azure Monitor Elevation of Privilege Vulnerability |
| CVE-2025-59245 | CRITICAL | 9.8 | 0.9% | Nov 20, 2025 | Microsoft SharePoint Online Elevation of Privilege Vulnerability |
| CVE-2025-49752 | CRITICAL | 10 | 0.9% | Nov 20, 2025 | Azure Bastion Elevation of Privilege Vulnerability |
| CVE-2025-63807 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (... |
| CVE-2025-63685 | CRITICAL | 9.8 | 0.3% | Nov 20, 2025 | Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of syste... |
| CVE-2025-10571 | CRITICAL | 9.6 | 0.3% | Nov 20, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB... |
| CVE-2025-63888 | CRITICAL | 9.8 | 0.5% | Nov 20, 2025 | The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code exec... |
| CVE-2025-64428 | CRITICAL | 9.8 | 0.5% | Nov 20, 2025 | Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection.... |
| CVE-2025-52410 | CRITICAL | 9.8 | 0.3% | Nov 20, 2025 | Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php e... |
| CVE-2025-60738 | CRITICAL | 9.8 | 0.9% | Nov 20, 2025 | An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before ... |
| CVE-2025-34320 | CRITICAL | 9.3 | 0.7% | Nov 20, 2025 | BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize in... |
| CVE-2025-40604 | CRITICAL | 9.8 | 0.2% | Nov 20, 2025 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem i... |
| CVE-2025-13451 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of... |
| CVE-2025-13449 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the fi... |
| CVE-2025-13446 | CRITICAL | 9.8 | 3.4% | Nov 20, 2025 | A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/Se... |
| CVE-2025-13445 | CRITICAL | 9.8 | 3.4% | Nov 20, 2025 | A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executin... |
| CVE-2025-13442 | CRITICAL | 9.8 | 17.6% | Nov 20, 2025 | A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the func... |
| CVE-2025-12414 | CRITICAL | 9.2 | 0.4% | Nov 20, 2025 | An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email addr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now