2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12183 | HIGH | 8.8 | 0.6% | Nov 28, 2025 | Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service ... |
| CVE-2025-51735 | HIGH | 7.5 | 0.3% | Nov 28, 2025 | CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-12638 | HIGH | 8 | 0.6% | Nov 28, 2025 | Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin... |
| CVE-2025-13771 | HIGH | 7.1 | 0.4% | Nov 28, 2025 | WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit ... |
| CVE-2025-13770 | HIGH | 7.1 | 0.3% | Nov 28, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar... |
| CVE-2025-13769 | HIGH | 7.1 | 0.3% | Nov 28, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar... |
| CVE-2025-13768 | HIGH | 8.8 | 0.4% | Nov 28, 2025 | WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in... |
| CVE-2025-66384 | HIGH | 8.2 | 0.3% | Nov 28, 2025 | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela... |
| CVE-2025-64312 | HIGH | 7.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma... |
| CVE-2025-58311 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availabili... |
| CVE-2025-64315 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-58314 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner... |
| CVE-2025-58309 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w... |
| CVE-2025-66360 | HIGH | 8.8 | 0.3% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo... |
| CVE-2025-13757 | HIGH | 8.8 | 0.5% | Nov 27, 2025 | SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025... |
| CVE-2025-13692 | HIGH | 7.2 | 0.3% | Nov 27, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2025-59890 | HIGH | 7.3 | 0.1% | Nov 27, 2025 | Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths ... |
| CVE-2025-13536 | HIGH | 8.8 | 0.5% | Nov 27, 2025 | The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida... |
| CVE-2025-7820 | HIGH | 7.5 | 0.3% | Nov 27, 2025 | The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including... |
| CVE-2025-13680 | HIGH | 8.8 | 0.2% | Nov 27, 2025 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ... |
| CVE-2025-12758 | HIGH | 7.7 | 0.5% | Nov 27, 2025 | Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe... |
| CVE-2025-66314 | HIGH | 7.5 | 0.2% | Nov 27, 2025 | Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper... |
| CVE-2025-0658 | HIGH | 8.7 | 0.3% | Nov 27, 2025 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev... |
| CVE-2025-0657 | HIGH | 8.8 | 0.3% | Nov 27, 2025 | A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed... |
| CVE-2025-66035 | HIGH | 7.7 | 0.6% | Nov 26, 2025 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now