2025 CVE Vulnerabilities

45,138 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-52635CRITICAL9.8A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION:...
CVE-2025-61928CRITICAL9.3Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated ...
CVE-2025-59286CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-59272CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-59252CRITICAL9.3Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at...
CVE-2025-59247CRITICAL9.8Azure PlayFab Elevation of Privilege Vulnerability
CVE-2025-59246CRITICAL9.8Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-59218CRITICAL9.6Azure Entra ID Elevation of Privilege Vulnerability
CVE-2025-55321CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor...
CVE-2025-35062CRITICAL9.8Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenti...
CVE-2025-35051CRITICAL9.8Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, al...
CVE-2025-35050CRITICAL9.8Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, u...
CVE-2025-11558CRITICAL9.8A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/us...
CVE-2025-11557CRITICAL9.8A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown process...
CVE-2025-11556CRITICAL9.8A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /us...
CVE-2025-11555CRITICAL9.8A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the fil...
CVE-2025-60316CRITICAL9.4SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID...
CVE-2025-11553CRITICAL9.8A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-11551CRITICAL9.8A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file...
CVE-2025-59978CRITICAL9.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-11549CRITICAL9.8A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the ...
CVE-2025-59974CRITICAL9.3An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Sec...
CVE-2025-10284CRITICAL9.6BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arb...
CVE-2025-10283CRITICAL9.6BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
CVE-2025-56683CRITICAL9.6A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to ...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now