2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6945 | LOW | 3.5 | 0.2% | Nov 15, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5... |
| CVE-2025-11990 | LOW | 3.5 | 0.3% | Nov 15, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.4, and 18.5 before 18.5.2 that ... |
| CVE-2025-54560 | LOW | 3.8 | 0.2% | Nov 14, 2025 | A Server-side Request Forgery vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0... |
| CVE-2025-54559 | LOW | 3.7 | 0.2% | Nov 14, 2025 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote ... |
| CVE-2025-54342 | LOW | 3.3 | 0.1% | Nov 14, 2025 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exp... |
| CVE-2025-4617 | LOW | 1.1 | 0.1% | Nov 14, 2025 | An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authe... |
| CVE-2025-4616 | LOW | 1.1 | 0.1% | Nov 14, 2025 | An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally au... |
| CVE-2025-64754 | LOW | 2.7 | 0.4% | Nov 13, 2025 | Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allo... |
| CVE-2025-64744 | LOW | 3.5 | 0.2% | Nov 13, 2025 | OpenObserve is a cloud-native observability platform. In versions up to and including 0.16.1, when creating or renaming ... |
| CVE-2025-12817 | LOW | 3.1 | 0.2% | Nov 13, 2025 | Missing authorization in PostgreSQL CREATE STATISTICS command allows a table owner to achieve denial of service against ... |
| CVE-2025-64503 | LOW | 3.3 | 0.2% | Nov 12, 2025 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operati... |
| CVE-2025-64345 | LOW | 1.8 | 0.1% | Nov 12, 2025 | Wasmtime is a runtime for WebAssembly. Prior to version 38.0.4, 37.0.3, 36.0.3, and 24.0.5, Wasmtime's Rust embedder API... |
| CVE-2025-64170 | LOW | 3.8 | 0.1% | Nov 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. Starting in version 0.2.7 and prior to version 0... |
| CVE-2025-63396 | LOW | 3.3 | 0.1% | Nov 12, 2025 | An issue was discovered in PyTorch v2.5 and v2.7.1. Omission of profiler.stop() can cause torch.profiler.profile (Python... |
| CVE-2025-57812 | LOW | 3.7 | 0.4% | Nov 12, 2025 | CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the for... |
| CVE-2025-20379 | LOW | 3.5 | 0.2% | Nov 12, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, and 9.2.9 and Splunk Cloud Platform versions below 9.3.2411.11... |
| CVE-2025-41116 | LOW | 2.1 | 0.2% | Nov 11, 2025 | When using the Grafana Databricks Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple use... |
| CVE-2025-3717 | LOW | 2.1 | 0.2% | Nov 11, 2025 | When using the Grafana Snowflake Datasource Plugin, if Oauth passthrough is enabled on the datasource, and multiple user... |
| CVE-2025-32088 | LOW | 3.3 | 0.1% | Nov 11, 2025 | Improper conditions check for some Intel(R) QAT Windows software before version 2.6.0. within Ring 3: User Applications ... |
| CVE-2025-32037 | LOW | 2 | 0.1% | Nov 11, 2025 | Improper access control for some Intel(R) PresentMon before version 2.3.1 within Ring 3: User Applications may allow a d... |
| CVE-2025-30509 | LOW | 3.3 | 0.1% | Nov 11, 2025 | Improper input validation for some Intel QuickAssist Technology software before version 2.6.0 within Ring 3: User Applic... |
| CVE-2025-25216 | LOW | 3.3 | 0.1% | Nov 11, 2025 | Improper input validation in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Devic... |
| CVE-2025-24862 | LOW | 2 | 0.2% | Nov 11, 2025 | Unrestricted upload of file with dangerous type for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within... |
| CVE-2025-24307 | LOW | 2.3 | 0.2% | Nov 11, 2025 | Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Appl... |
| CVE-2025-20622 | LOW | 3.8 | 0.1% | Nov 11, 2025 | Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before ve... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now