2025 CVE Vulnerabilities

45,223 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-21044MEDIUM4.4Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write o...
CVE-2025-10124MEDIUM4.5The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode...
CVE-2025-61871HIGH8.4NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w...
CVE-2025-11570MEDIUM4.6Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XS...
CVE-2025-11569Rejected reason: This record was withdrawn by its CNA; further investigation revealed it was not a security issue.
CVE-2025-11450MEDIUM5.3ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor...
CVE-2025-11449MEDIUM5.3ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor...
CVE-2025-61928CRITICAL9.3Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated ...
CVE-2025-61926MEDIUM4.6Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev...
CVE-2025-62240MEDIUM5.4Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, a...
CVE-2025-61783MEDIUM6.3Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, t...
CVE-2025-61779HIGH8.7Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing ...
CVE-2025-61773HIGH8.1pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte...
CVE-2025-61602HIGH7.5BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 a...
CVE-2025-61601HIGH7.5BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 a...
CVE-2025-60375HIGH7.3The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient...
CVE-2025-59286CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-59272CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-59271HIGH8.7Redis Enterprise Elevation of Privilege Vulnerability
CVE-2025-59252CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-59247CRITICAL9.8Azure PlayFab Elevation of Privilege Vulnerability
CVE-2025-59246CRITICAL9.8Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59218CRITICAL9.6Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55321CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor...
CVE-2025-43296MEDIUM5.5A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now