2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65942 | LOW | 2.7 | 0.3% | Nov 25, 2025 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.... |
| CVE-2025-33200 | LOW | 3.3 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... |
| CVE-2025-33199 | LOW | 3.8 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause incorrect control flow b... |
| CVE-2025-33198 | LOW | 3.3 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... |
| CVE-2025-13596 | LOW | 2.7 | 0.3% | Nov 24, 2025 | A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Applicati... |
| CVE-2025-13584 | LOW | 3.5 | 0.2% | Nov 24, 2025 | A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the com... |
| CVE-2025-54515 | LOW | 1 | 0.1% | Nov 23, 2025 | The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State ... |
| CVE-2025-11934 | LOW | 2.7 | 0.1% | Nov 21, 2025 | Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier ... |
| CVE-2025-31216 | LOW | 2.4 | 0.1% | Nov 21, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke... |
| CVE-2025-66062 | LOW | 3.4 | 0.2% | Nov 21, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allo... |
| CVE-2025-64299 | LOW | 2.7 | 0.2% | Nov 21, 2025 | LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' passwor... |
| CVE-2025-52666 | LOW | 2.7 | 0.4% | Nov 20, 2025 | Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions cau... |
| CVE-2025-13425 | LOW | 1.9 | 0.1% | Nov 20, 2025 | A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice wh... |
| CVE-2025-11884 | LOW | 2.3 | 0.2% | Nov 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uC... |
| CVE-2025-64757 | LOW | 3.5 | 0.4% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm... |
| CVE-2025-65014 | LOW | 3.7 | 0.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password ... |
| CVE-2025-12119 | LOW | 3.3 | 0.2% | Nov 18, 2025 | A mongoc_bulk_operation_t may read invalid memory if large options are passed. |
| CVE-2025-13083 | LOW | 3.7 | 0.2% | Nov 18, 2025 | Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrec... |
| CVE-2025-12761 | LOW | 3.5 | 0.1% | Nov 18, 2025 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple mult... |
| CVE-2025-55074 | LOW | 3.5 | 0.1% | Nov 18, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which ... |
| CVE-2025-64734 | LOW | 2.4 | 0.1% | Nov 18, 2025 | Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access... |
| CVE-2025-12792 | LOW | 3.2 | 0.1% | Nov 18, 2025 | The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A loc... |
| CVE-2025-63292 | LOW | 3.5 | 0.1% | Nov 17, 2025 | Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x... |
| CVE-2025-65083 | LOW | 3.2 | 0.1% | Nov 17, 2025 | GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be prob... |
| CVE-2025-13232 | LOW | 3.5 | 0.2% | Nov 16, 2025 | A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Do... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now