2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66031 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R... |
| CVE-2025-64344 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64335 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64334 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64333 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64332 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64331 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64330 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-65202 | HIGH | 8 | 7.2% | Nov 26, 2025 | TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, explo... |
| CVE-2025-65278 | HIGH | 7.5 | 0.2% | Nov 26, 2025 | An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers... |
| CVE-2025-12571 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and ... |
| CVE-2025-66028 | HIGH | 8.2 | 0.3% | Nov 26, 2025 | OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable ... |
| CVE-2025-65966 | HIGH | 8.1 | 0.3% | Nov 26, 2025 | OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea... |
| CVE-2025-65672 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course sett... |
| CVE-2025-64129 | HIGH | 7.6 | 0.4% | Nov 26, 2025 | Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the... |
| CVE-2025-55471 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive inf... |
| CVE-2025-2486 | HIGH | 8.8 | 0.1% | Nov 26, 2025 | The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, p... |
| CVE-2025-13084 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ... |
| CVE-2025-11461 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int... |
| CVE-2025-46175 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the au... |
| CVE-2025-56396 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi... |
| CVE-2025-46174 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the reset... |
| CVE-2025-45311 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary opera... |
| CVE-2025-13601 | HIGH | 7.7 | 0.3% | Nov 26, 2025 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_u... |
| CVE-2025-13735 | HIGH | 7.4 | 0.2% | Nov 26, 2025 | Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now