2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13122 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | A vulnerability was detected in SourceCodester Patients Waiting Area Queue Management System 1.0. The affected element i... |
| CVE-2025-64717 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4,... |
| CVE-2025-62484 | CRITICAL | 9.8 | 0.3% | Nov 13, 2025 | Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthent... |
| CVE-2025-64741 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | Improper authorization handling in Zoom Workplace for Android before version 6.5.10 may allow an unauthenticated user to... |
| CVE-2025-12762 | CRITICAL | 9.8 | 12.0% | Nov 13, 2025 | pgAdmin versions up to 9.9 are affected by a Remote Code Execution (RCE) vulnerability that occurs when running in serve... |
| CVE-2025-59367 | CRITICAL | 9.8 | 0.8% | Nov 13, 2025 | An authentication bypass vulnerability has been identified in certain DSL series routers, may allow remote attackers to ... |
| CVE-2025-13076 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the fil... |
| CVE-2025-13075 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /ad... |
| CVE-2025-13060 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | A security vulnerability has been detected in SourceCodester Survey Application System 1.0. This affects an unknown func... |
| CVE-2025-13059 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A weakness has been identified in SourceCodester Alumni Management System 1.0. The impacted element is an unknown functi... |
| CVE-2025-56385 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | A SQL injection vulnerability exists in the login functionality of WellSky Harmony version 4.1.0.2.83 within the 'xmHarm... |
| CVE-2025-13057 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Impacted is an unknown function o... |
| CVE-2025-64281 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel ... |
| CVE-2025-64280 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permi... |
| CVE-2025-63353 | CRITICAL | 9.8 | 1.2% | Nov 12, 2025 | A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s... |
| CVE-2025-63289 | CRITICAL | 9.1 | 0.2% | Nov 12, 2025 | Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryptio... |
| CVE-2025-11367 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization |
| CVE-2025-11366 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | N-central < 2025.4 is vulnerable to authentication bypass via path traversal |
| CVE-2025-63666 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and ... |
| CVE-2025-40176 | CRITICAL | 9.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp... |
| CVE-2025-12871 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to c... |
| CVE-2025-12870 | CRITICAL | 9.8 | 0.6% | Nov 12, 2025 | The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to s... |
| CVE-2025-60724 | CRITICAL | 9.8 | 5.8% | Nov 11, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a networ... |
| CVE-2025-13026 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F... |
| CVE-2025-13024 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now