2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54339 | CRITICAL | 10 | 0.3% | Nov 14, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-64446 | CRITICAL | 9.8 | 89.5% | Nov 14, 2025 | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb... |
| CVE-2025-13170 | CRITICAL | 9.8 | 0.3% | Nov 14, 2025 | A vulnerability was detected in code-projects Simple Online Hotel Reservation System 1.0. This issue affects some unknow... |
| CVE-2025-13169 | CRITICAL | 9.8 | 0.4% | Nov 14, 2025 | A security vulnerability has been detected in code-projects Simple Online Hotel Reservation System 1.0. This vulnerabili... |
| CVE-2025-13168 | CRITICAL | 9.8 | 0.3% | Nov 14, 2025 | A weakness has been identified in ury-erp ury up to 0.2.0. This affects the function overrided_past_order_list of the fi... |
| CVE-2025-36251 | CRITICAL | 9.8 | 0.5% | Nov 13, 2025 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 nimsh service SSL/TLS implementations could allow a remote attacker to ex... |
| CVE-2025-36250 | CRITICAL | 9.8 | 0.6% | Nov 13, 2025 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a... |
| CVE-2025-36236 | CRITICAL | 9.1 | 0.4% | Nov 13, 2025 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 NIM server (formerly known as NIM master) service (nimesis) could allow a... |
| CVE-2025-64709 | CRITICAL | 9.9 | 0.3% | Nov 13, 2025 | Typebot is an open-source chatbot builder. In versions prior to 3.13.1, a Server-Side Request Forgery (SSRF) vulnerabili... |
| CVE-2025-13123 | CRITICAL | 9.8 | 0.3% | Nov 13, 2025 | A flaw has been found in AMTT Hotel Broadband Operation System 1.0. The impacted element is an unknown function of the f... |
| CVE-2025-13122 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element i... |
| CVE-2025-64717 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4,... |
| CVE-2025-62484 | CRITICAL | 9.8 | 0.3% | Nov 13, 2025 | Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthent... |
| CVE-2025-64741 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to... |
| CVE-2025-12762 | CRITICAL | 9.8 | 12.0% | Nov 13, 2025 | pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in serve... |
| CVE-2025-59367 | CRITICAL | 9.8 | 0.8% | Nov 13, 2025 | An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to ... |
| CVE-2025-13076 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the fil... |
| CVE-2025-13075 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /ad... |
| CVE-2025-13060 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown func... |
| CVE-2025-13059 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown functi... |
| CVE-2025-56385 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarm... |
| CVE-2025-13057 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function o... |
| CVE-2025-64281 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel ... |
| CVE-2025-64280 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permi... |
| CVE-2025-63353 | CRITICAL | 9.8 | 1.2% | Nov 12, 2025 | A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now