2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11601 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was detected in SourceCodester Online Student Result System 1.0. Affected by this vulnerability is an un... |
| CVE-2025-11599 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A weakness has been identified in Campcodes Online Apartment Visitor Management System 1.0. This impacts an unknown func... |
| CVE-2025-11597 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was identified in code-projects E-Commerce Website 1.0. The impacted element is an unknown function of t... |
| CVE-2025-6439 | CRITICAL | 9.8 | 0.7% | Oct 11, 2025 | The WooCommerce Designer Pro plugin for WordPress, used by the Pricom - Printing Company & Design Services WordPress the... |
| CVE-2025-11596 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was determined in code-projects E-Commerce Website 1.0. The affected element is an unknown function of t... |
| CVE-2025-11595 | CRITICAL | 9.8 | 0.4% | Oct 11, 2025 | A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function o... |
| CVE-2025-6553 | CRITICAL | 9.8 | 0.7% | Oct 11, 2025 | The Ovatheme Events Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valida... |
| CVE-2025-11533 | CRITICAL | 9.8 | 0.6% | Oct 11, 2025 | The WP Freeio plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2.21. T... |
| CVE-2025-11586 | CRITICAL | 9.8 | 0.8% | Oct 10, 2025 | A vulnerability was determined in Tenda AC7 15.03.06.44. This affects an unknown function of the file /goform/setNotUpgr... |
| CVE-2025-11585 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability was found in code-projects Project Monitoring System 1.0. The impacted element is an unknown function of... |
| CVE-2025-11584 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability has been found in code-projects Online Job Search Engine 1.0. The affected element is an unknown functio... |
| CVE-2025-61929 | CRITICAL | 9.6 | 0.4% | Oct 10, 2025 | Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol ca... |
| CVE-2025-11583 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A flaw has been found in code-projects Online Job Search Engine 1.0. Impacted is an unknown function of the file /postjo... |
| CVE-2025-11582 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This issue affects some unknown processing o... |
| CVE-2025-60306 | CRITICAL | 9.9 | 0.4% | Oct 10, 2025 | code-projects Simple Car Rental System 1.0 has a permission bypass issue where low privilege users can forge high privil... |
| CVE-2025-60269 | CRITICAL | 9.4 | 0.3% | Oct 10, 2025 | JEEWMS 20250820 is vulnerable to SQL Injection in the exportXls function located in the src/main/java/org/jeecgframework... |
| CVE-2025-60307 | CRITICAL | 9.8 | 0.4% | Oct 10, 2025 | code-projects Computer Laboratory System 1.0 has a SQL injection vulnerability, where entering a universal password in t... |
| CVE-2025-52635 | CRITICAL | 9.8 | 0.2% | Oct 10, 2025 | A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION:... |
| CVE-2025-61928 | CRITICAL | 9.3 | 18.0% | Oct 9, 2025 | Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated ... |
| CVE-2025-59286 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59272 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59252 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59247 | CRITICAL | 9.8 | 1.4% | Oct 9, 2025 | Azure PlayFab Elevation of Privilege Vulnerability |
| CVE-2025-59246 | CRITICAL | 9.8 | 6.9% | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59218 | CRITICAL | 9.6 | 0.6% | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now