2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-11127CRITICAL9.8The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly ve...
CVE-2025-11456CRITICAL9.8The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to arbitrary file uploads due...
CVE-2025-64310CRITICAL9.8EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attemp...
CVE-2025-64762CRITICAL9.1The AuthKit library for Next.js provides convenient helpers for authentication and session management using WorkOS & Aut...
CVE-2025-64755CRITICAL9.8Claude Code is an agentic coding tool. Prior to version 2.0.31, due to an error in sed command parsing, it was possible ...
CVE-2025-13485CRITICAL9.8A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown p...
CVE-2025-64655CRITICAL9.8Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privile...
CVE-2025-62207CRITICAL9.8Azure Monitor Elevation of Privilege Vulnerability
CVE-2025-59245CRITICAL9.8Microsoft SharePoint Online Elevation of Privilege Vulnerability
CVE-2025-49752CRITICAL10Azure Bastion Elevation of Privilege Vulnerability
CVE-2025-63807CRITICAL9.8An issue was discovered in weijiang1994 university-bbs (aka Blogin) in commit 9e06bab430bfc729f27b4284ba7570db3b11ce84 (...
CVE-2025-63685CRITICAL9.8Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of syste...
CVE-2025-10571CRITICAL9.6Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB...
CVE-2025-63888CRITICAL9.8The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code exec...
CVE-2025-64428CRITICAL9.8Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection....
CVE-2025-52410CRITICAL9.8Institute-of-Current-Students v1.0 contains a time-based blind SQL injection vulnerability in the mydetailsstudent.php e...
CVE-2025-60738CRITICAL9.8An issue in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before Logic Version v6.00 - 2025_07_21 and before ...
CVE-2025-34320CRITICAL9.3BASIS BBj versions prior to 25.00 contain a Jetty-served web endpoint that fails to properly validate or canonicalize in...
CVE-2025-40604CRITICAL9.8Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem i...
CVE-2025-13451CRITICAL9.8A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of...
CVE-2025-13449CRITICAL9.8A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the fi...
CVE-2025-13446CRITICAL9.8A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/Se...
CVE-2025-13445CRITICAL9.8A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executin...
CVE-2025-13442CRITICAL9.8A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the func...
CVE-2025-12414CRITICAL9.2An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email addr...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now