2025 CVE Vulnerabilities

45,320 CVEs published in 2025.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2025-55321CRITICAL9.3Improper neutralization of input during web page generation ('cross-site scripting') in Azure Monitor allows an unauthor...
CVE-2025-35062CRITICAL9.8Newforma Info Exchange (NIX) before version 2023.1 by default allows anonymous authentication which allows an unauthenti...
CVE-2025-35051CRITICAL9.8Newforma Project Center Server (NPCS) accepts serialized .NET data via the '/ProjectCenter.rem' endpoint on 9003/tcp, al...
CVE-2025-35050CRITICAL9.8Newforma Info Exchange (NIX) accepts serialized .NET data via the '/remoteweb/remote.rem' endpoint, allowing a remote, u...
CVE-2025-11558CRITICAL9.8A vulnerability was found in code-projects E-Commerce Website 1.0. Impacted is an unknown function of the file /pages/us...
CVE-2025-11557CRITICAL9.8A vulnerability has been found in projectworlds Gate Pass Management System 1.0. This issue affects some unknown process...
CVE-2025-11556CRITICAL9.8A flaw has been found in code-projects Simple Leave Manager 1.0. This vulnerability affects unknown code of the file /us...
CVE-2025-11555CRITICAL9.8A vulnerability was detected in Campcodes Online Learning Management System 1.0. This affects an unknown part of the fil...
CVE-2025-60316CRITICAL9.4SourceCodester Pet Grooming Management Software 1.0 is vulnerable to SQL Injection in admin/view_customer.php via the ID...
CVE-2025-11553CRITICAL9.8A weakness has been identified in code-projects Courier Management System 1.0. Affected by this vulnerability is an unkn...
CVE-2025-11551CRITICAL9.8A vulnerability was determined in code-projects Student Result Manager 1.0. This affects an unknown function of the file...
CVE-2025-59978CRITICAL9.4An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Network...
CVE-2025-11549CRITICAL9.8A vulnerability has been found in Tenda W12 3.0.0.6(3948). The affected element is the function wifiMacFilterSet of the ...
CVE-2025-59974CRITICAL9.3An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Junos Space Sec...
CVE-2025-10284CRITICAL9.6BBOT's unarchive module could be abused by supplying malicious archives files and when extracted can then perform an arb...
CVE-2025-10283CRITICAL9.6BBOT's gitdumper module could be abused to execute commands through a malicious git repository.
CVE-2025-56683CRITICAL9.6A cross-site scripting (XSS) vulnerability in the component /app/marketplace.html of Logseq v0.10.9 allows attackers to ...
CVE-2025-11539CRITICAL9.9Grafana Image Renderer is vulnerable to remote code execution due to an arbitrary file write vulnerability. This is due ...
CVE-2025-11522CRITICAL9.8The Search & Go - Directory WordPress Theme theme for WordPress is vulnerable to Authentication Bypass via account takeo...
CVE-2025-7634CRITICAL9.8The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to Local File Inc...
CVE-2025-7526CRITICAL9.8The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to arbitrary file...
CVE-2025-11529CRITICAL9.8A security flaw has been discovered in ChurchCRM up to 5.18.0. This impacts the function AuthMiddleware of the file src/...
CVE-2025-10586CRITICAL9.8The Community Events plugin for WordPress is vulnerable to SQL Injection via the ‘event_venue’ parameter in all versions...
CVE-2025-11513CRITICAL9.8A vulnerability was determined in code-projects E-Commerce Website 1.0. This affects an unknown part of the file /pages/...
CVE-2025-61913CRITICAL9.9Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, Wri...

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now