2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64773 | LOW | 3.7 | 0.2% | Nov 11, 2025 | In JetBrains YouTrack before 2025.3.104432 a race condition allowed bypass of helpdesk Agent limit |
| CVE-2025-13015 | LOW | 3.4 | 0.2% | Nov 11, 2025 | Spoofing issue in Firefox. This vulnerability was fixed in Firefox 145, Firefox ESR 140.5, and Firefox ESR 115.30. |
| CVE-2025-8998 | LOW | 3.1 | 0.2% | Nov 11, 2025 | It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and i... |
| CVE-2025-42883 | LOW | 2.7 | 0.2% | Nov 11, 2025 | Migration Workbench (DX Workbench) in SAP NetWeaver Application Server for ABAP fails to trigger a malware scan when an ... |
| CVE-2025-64682 | LOW | 3.7 | 0.1% | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 a race condition allowed bypass of the Agent-user limit |
| CVE-2025-64681 | LOW | 3.7 | 0.2% | Nov 10, 2025 | In JetBrains Hub before 2025.3.104992 a race condition allowed bypass of the user limit via invitations |
| CVE-2025-12919 | LOW | 3.7 | 0.4% | Nov 9, 2025 | A vulnerability was detected in EverShop up to 2.0.1. Affected is an unknown function of the file /src/modules/oms/graph... |
| CVE-2025-64481 | LOW | 2.7 | 0.4% | Nov 7, 2025 | Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through... |
| CVE-2025-12854 | LOW | 3.7 | 0.4% | Nov 7, 2025 | A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill o... |
| CVE-2025-11219 | LOW | 3.1 | 0.2% | Nov 6, 2025 | Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bou... |
| CVE-2025-64326 | LOW | 3.5 | 0.2% | Nov 6, 2025 | Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project membe... |
| CVE-2025-21077 | LOW | 3.3 | 0.1% | Nov 5, 2025 | Improper input validation in Samsung Email prior to version 6.2.06.0 allows local attackers to launch arbitrary activity... |
| CVE-2025-43442 | LOW | 3.3 | 0.2% | Nov 4, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS... |
| CVE-2025-43423 | LOW | 2 | 0.2% | Nov 4, 2025 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.... |
| CVE-2025-43408 | LOW | 2.4 | 0.2% | Nov 4, 2025 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in macOS Sequoia 15.7.2,... |
| CVE-2025-43395 | LOW | 3.3 | 0.2% | Nov 4, 2025 | This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1... |
| CVE-2025-43365 | LOW | 2.8 | 0.1% | Nov 4, 2025 | A denial-of-service issue was addressed with improved input validation. This issue is fixed in iOS 18.7.2 and iPadOS 18.... |
| CVE-2025-43350 | LOW | 2.4 | 0.2% | Nov 4, 2025 | A permissions issue was addressed with additional restrictions. This issue is fixed in iOS 26.1 and iPadOS 26.1. An atta... |
| CVE-2025-43309 | LOW | 2.4 | 0.1% | Nov 4, 2025 | A logic issue was addressed with improved checks. This issue is fixed in iOS 26 and iPadOS 26. An attacker with physical... |
| CVE-2025-12623 | LOW | 3.1 | 0.3% | Nov 3, 2025 | A vulnerability was identified in fushengqian fuint up to 41e26be8a2c609413a0feaa69bdad33a71ae8032. Affected by this iss... |
| CVE-2025-64352 | LOW | 2.7 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in WPDeveloper Essential Addons for Elementor essential-addons-for-elementor-lite al... |
| CVE-2025-64350 | LOW | 3.8 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Exploiting Incorrectly Config... |
| CVE-2025-23050 | LOW | 3.1 | 0.2% | Oct 31, 2025 | QLowEnergyController in Qt before 6.8.2 mishandles malformed Bluetooth ATT commands, leading to an out-of-bounds read (o... |
| CVE-2025-10636 | LOW | 3.5 | 0.2% | Oct 30, 2025 | The NS Maintenance Mode for WP WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which c... |
| CVE-2025-10931 | LOW | 3.8 | 0.2% | Oct 30, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Umami Analy... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now