2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52635 | CRITICAL | 9.8 | 0.2% | Oct 10, 2025 | A rusted types in scripts not enforced in CSP vulnerability has been identified in HCL AION.This issue affects AION:... |
| CVE-2025-61928 | CRITICAL | 9.3 | 18.0% | Oct 9, 2025 | Better Auth is an authentication and authorization library for TypeScript. In versions prior to 1.3.26, unauthenticated ... |
| CVE-2025-59286 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59272 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59252 | CRITICAL | 9.3 | 0.5% | Oct 9, 2025 | Improper neutralization of special elements used in a command ('command injection') in Copilot allows an unauthorized at... |
| CVE-2025-59247 | CRITICAL | 9.8 | 1.4% | Oct 9, 2025 | Azure PlayFab Elevation of Privilege Vulnerability |
| CVE-2025-59246 | CRITICAL | 9.8 | 6.9% | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-59218 | CRITICAL | 9.6 | 0.6% | Oct 9, 2025 | Azure Entra ID Elevation of Privilege Vulnerability |
| CVE-2025-55321 | CRITICAL | 9.3 | 0.4% | Oct 9, 2025 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor... |
| CVE-2025-35062 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenti... |
| CVE-2025-35051 | CRITICAL | 9.8 | 0.8% | Oct 9, 2025 | Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, al... |
| CVE-2025-35050 | CRITICAL | 9.8 | 0.8% | Oct 9, 2025 | Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, u... |
| CVE-2025-11558 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/us... |
| CVE-2025-11557 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown process... |
| CVE-2025-11556 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /us... |
| CVE-2025-11555 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the fil... |
| CVE-2025-60316 | CRITICAL | 9.4 | 0.3% | Oct 9, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID... |
| CVE-2025-11553 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-11551 | CRITICAL | 9.8 | 0.4% | Oct 9, 2025 | A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file... |
| CVE-2025-59978 | CRITICAL | 9.4 | 0.6% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network... |
| CVE-2025-11549 | CRITICAL | 9.8 | 7.9% | Oct 9, 2025 | A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the ... |
| CVE-2025-59974 | CRITICAL | 9.3 | 0.3% | Oct 9, 2025 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Sec... |
| CVE-2025-10284 | CRITICAL | 9.6 | 0.7% | Oct 9, 2025 | BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arb... |
| CVE-2025-10283 | CRITICAL | 9.6 | 0.4% | Oct 9, 2025 | BBOT's gitdumper module could be abused to execute commands through a malicious git repository. |
| CVE-2025-56683 | CRITICAL | 9.6 | 0.4% | Oct 9, 2025 | A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now