2025 CVE Vulnerabilities
45,224 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43296 | MEDIUM | 5.5 | 0.1% | Oct 9, 2025 | A logic issue was addressed with improved validation. This issue is fixed in macOS Tahoe 26. An app may bypass Gatekeepe... |
| CVE-2025-35062 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenti... |
| CVE-2025-35061 | MEDIUM | 5.9 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/NPCSRemoteWeb/LegacyIntegrationServices.asmx' allows a remote, unauthenticated attacker t... |
| CVE-2025-35060 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | Newforma Info Exchange (NIX) provides a 'Send a File Transfer' feature that allows a remote, authenticated attacker to u... |
| CVE-2025-35059 | MEDIUM | 6.1 | 0.2% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/DownloadWeb/hyperlinkredirect.aspx' provides an unauthenticated URL redirect via the 'nhl... |
| CVE-2025-35058 | MEDIUM | 5.9 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' allows a remote, unauthenticated attacker to cause NI... |
| CVE-2025-35057 | MEDIUM | 6 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/RemoteWeb/IntegrationServices.ashx' allows a remote, unauthenticated attacker to cause NI... |
| CVE-2025-35056 | MEDIUM | 5 | 0.3% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/MarkupServices.ashx' 'StreamStampImage' accepts an encrypted file path and... |
| CVE-2025-35055 | HIGH | 8.8 | 0.5% | Oct 9, 2025 | Newforma Info Exchange (NIX) '/UserWeb/Common/UploadBlueimp.ashx' allows an authenticated attacker to upload an arbitrar... |
| CVE-2025-35054 | MEDIUM | 5.3 | 0.1% | Oct 9, 2025 | Newforma Info Exchange (NIX) stores credentials used to configure NPCS in 'HKLM\Software\WOW6432Node\Newforma\<version>... |
| CVE-2025-35053 | MEDIUM | 6.4 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) accepts requests to '/UserWeb/Common/MarkupServices.ashx' specifying the 'DownloadExportedP... |
| CVE-2025-35052 | MEDIUM | 6.3 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) uses a hard-coded key to encrypt certain query parameters. Some encrypted parameter values ... |
| CVE-2025-35051 | CRITICAL | 9.8 | 0.8% | Oct 9, 2025 | Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, al... |
| CVE-2025-35050 | CRITICAL | 9.8 | 0.8% | Oct 9, 2025 | Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, u... |
| CVE-2025-34248 | HIGH | 7.2 | 0.6% | Oct 9, 2025 | D-Link Nuclias Connect firmware versions < 1.3.1.4 contain a directory traversal vulnerability within /api/web/dnc/globa... |
| CVE-2025-11558 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/us... |
| CVE-2025-11557 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown process... |
| CVE-2025-11556 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /us... |
| CVE-2025-11555 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the fil... |
| CVE-2025-60316 | CRITICAL | 9.4 | 0.3% | Oct 9, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID... |
| CVE-2025-11554 | HIGH | 8.8 | 0.3% | Oct 9, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown f... |
| CVE-2025-11553 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-59146 | HIGH | 8.5 | 0.2% | Oct 9, 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticate... |
| CVE-2025-55200 | MEDIUM | 5.4 | 0.2% | Oct 9, 2025 | BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.13, the "Shared Notes" feature contains a St... |
| CVE-2025-4615 | HIGH | 7.2 | 0.7% | Oct 9, 2025 | An improper input neutralization vulnerability in the management web interface of the Palo Alto Networks PAN-OS® softwar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now