2025 CVE Vulnerabilities
45,223 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-21044 | MEDIUM | 4.4 | 0.1% | Oct 10, 2025 | Out-of-bounds write in fingerprint trustlet prior to SMR Oct-2025 Release 1 allows local privileged attackers to write o... |
| CVE-2025-10124 | MEDIUM | 4.5 | 0.2% | Oct 10, 2025 | The Booking Manager WordPress plugin before 2.1.15 registers a shortcode that deletes bookings and makes that shortcode... |
| CVE-2025-61871 | HIGH | 8.4 | 0.2% | Oct 10, 2025 | NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the w... |
| CVE-2025-11570 | MEDIUM | 4.6 | 0.2% | Oct 10, 2025 | Versions of the package drupal-pattern-lab/unified-twig-extensions from 0.0.0 are vulnerable to Cross-site Scripting (XS... |
| CVE-2025-11569 | — | — | — | Oct 10, 2025 | Rejected reason: This record was withdrawn by its CNA; further investigation revealed it was not a security issue. |
| CVE-2025-11450 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor... |
| CVE-2025-11449 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platfor... |
| CVE-2025-61928 | CRITICAL | 9.3 | 18.0% | Oct 9, 2025 | Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated ... |
| CVE-2025-61926 | MEDIUM | 4.6 | 0.4% | Oct 9, 2025 | Allstar is a GitHub App to set and enforce security policies. In versions prior to 4.5, a vulnerability in Allstar’s Rev... |
| CVE-2025-62240 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | Multiple cross-site scripting (XSS) vulnerabilities with Calendar events in Liferay Portal 7.4.3.35 through 7.4.3.111, a... |
| CVE-2025-61783 | MEDIUM | 6.3 | 0.5% | Oct 9, 2025 | Python Social Auth is a social authentication/registration mechanism. In versions prior to 5.6.0, upon authentication, t... |
| CVE-2025-61779 | HIGH | 8.7 | 0.3% | Oct 9, 2025 | Confidential Containers's Trustee project contains tools and components for attesting confidential guests and providing ... |
| CVE-2025-61773 | HIGH | 8.1 | 0.4% | Oct 9, 2025 | pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web inte... |
| CVE-2025-61602 | HIGH | 7.5 | 0.4% | Oct 9, 2025 | BigBlueButton is an open-source virtual classroom. A denial-of-service (DoS) vulnerability in versions prior to 3.0.13 a... |
| CVE-2025-61601 | HIGH | 7.5 | 0.4% | Oct 9, 2025 | BigBlueButton is an open-source virtual classroom. A Denial of Service (DoS) vulnerability in versions prior to 3.0.13 a... |
| CVE-2025-60375 | HIGH | 7.3 | 0.3% | Oct 9, 2025 | The authentication mechanism in Perfex CRM before 3.3.1 allows attackers to bypass login credentials due to insufficient... |
| CVE-2025-59286 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59272 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59271 | HIGH | 8.7 | 0.6% | Oct 9, 2025 | Redis Enterprise Elevation of Privilege Vulnerability |
| CVE-2025-59252 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59247 | CRITICAL | 9.8 | 1.4% | Oct 9, 2025 | Azure PlayFab Elevation of Privilege Vulnerability |
| CVE-2025-59246 | CRITICAL | 9.8 | 6.9% | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59218 | CRITICAL | 9.6 | 0.6% | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-55321 | CRITICAL | 9.3 | 0.4% | Oct 9, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor... |
| CVE-2025-43296 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now