2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13584 | LOW | 3.5 | 0.2% | Nov 24, 2025 | A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the com... |
| CVE-2025-54515 | LOW | 1 | 0.1% | Nov 23, 2025 | The Secure Flag passed to Versal™ Adaptive SoC’s Trusted Firmware for Cortex®-A processors (TF-A) for Arm’s Power State ... |
| CVE-2025-11934 | LOW | 2.7 | 0.1% | Nov 21, 2025 | Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier ... |
| CVE-2025-31216 | LOW | 2.4 | 0.1% | Nov 21, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke... |
| CVE-2025-66062 | LOW | 3.4 | 0.2% | Nov 21, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Frank Goossens WP YouTube Lyte wp-youtube-lyte allo... |
| CVE-2025-64299 | LOW | 2.7 | 0.2% | Nov 21, 2025 | LogStare Collector improperly handles the password hash data. An administrative user may obtain the other users' passwor... |
| CVE-2025-52666 | LOW | 2.7 | 0.4% | Nov 20, 2025 | Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions cau... |
| CVE-2025-13425 | LOW | 1.9 | 0.1% | Nov 20, 2025 | A bug in the filesystem traversal fallback path causes fs/diriterate/diriterate.go:Next() to overindex an empty slice wh... |
| CVE-2025-11884 | LOW | 2.3 | 0.2% | Nov 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uC... |
| CVE-2025-64757 | LOW | 3.5 | 0.4% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.14.3, a vulnerability has been identified in the Astro framework's developm... |
| CVE-2025-65014 | LOW | 3.7 | 0.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password ... |
| CVE-2025-12119 | LOW | 3.3 | 0.2% | Nov 18, 2025 | A mongoc_bulk_operation_t may read invalid memory if large options are passed. |
| CVE-2025-13083 | LOW | 3.7 | 0.2% | Nov 18, 2025 | Use of Web Browser Cache Containing Sensitive Information vulnerability in Drupal Drupal core allows Exploiting Incorrec... |
| CVE-2025-12761 | LOW | 3.5 | 0.1% | Nov 18, 2025 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple mult... |
| CVE-2025-55074 | LOW | 3.5 | 0.1% | Nov 18, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which ... |
| CVE-2025-64734 | LOW | 2.4 | 0.1% | Nov 18, 2025 | Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access... |
| CVE-2025-12792 | LOW | 3.2 | 0.1% | Nov 18, 2025 | The Mac App Store distribution of the Canva for Mac desktop app before 1.117.1 was built without Hardened Runtime. A loc... |
| CVE-2025-63292 | LOW | 3.5 | 0.1% | Nov 17, 2025 | Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x... |
| CVE-2025-65083 | LOW | 3.2 | 0.1% | Nov 17, 2025 | GoSign Desktop through 2.4.1 disables TLS certificate validation when configured to use a proxy server. This can be prob... |
| CVE-2025-13232 | LOW | 3.5 | 0.2% | Nov 16, 2025 | A flaw has been found in projectsend up to r1720. Impacted is an unknown function of the component File Editor/Custom Do... |
| CVE-2025-6945 | LOW | 3.5 | 0.2% | Nov 15, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5... |
| CVE-2025-11990 | LOW | 3.5 | 0.3% | Nov 15, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that ... |
| CVE-2025-54560 | LOW | 3.8 | 0.2% | Nov 14, 2025 | A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0... |
| CVE-2025-54559 | LOW | 3.7 | 0.2% | Nov 14, 2025 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote ... |
| CVE-2025-54342 | LOW | 3.3 | 0.1% | Nov 14, 2025 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now