2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9558 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received... |
| CVE-2025-9557 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi... |
| CVE-2025-12061 | HIGH | 8.6 | 0.2% | Nov 26, 2025 | The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, a... |
| CVE-2025-64983 | HIGH | 8.6 | 0.3% | Nov 26, 2025 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac... |
| CVE-2025-66269 | HIGH | 7.1 | 0.1% | Nov 26, 2025 | The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all... |
| CVE-2025-66020 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i... |
| CVE-2025-66264 | HIGH | 7.2 | 0.1% | Nov 26, 2025 | The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke... |
| CVE-2025-66263 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66252 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte... |
| CVE-2025-65957 | HIGH | 8.8 | 0.2% | Nov 26, 2025 | Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_... |
| CVE-2025-65952 | HIGH | 8.7 | 0.4% | Nov 25, 2025 | Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p... |
| CVE-2025-64713 | HIGH | 7.4 | 0.3% | Nov 25, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-... |
| CVE-2025-62703 | HIGH | 8.8 | 0.7% | Nov 25, 2025 | Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Da... |
| CVE-2025-51741 | HIGH | 7.5 | 0.4% | Nov 25, 2025 | An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to... |
| CVE-2025-9624 | HIGH | 7.5 | 0.5% | Nov 25, 2025 | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input... |
| CVE-2025-66017 | HIGH | 8.2 | 0.2% | Nov 25, 2025 | CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab... |
| CVE-2025-65965 | HIGH | 8.2 | 0.1% | Nov 25, 2025 | Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found i... |
| CVE-2025-12816 | HIGH | 8.6 | 0.7% | Nov 25, 2025 | An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated atta... |
| CVE-2025-64065 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | The Primakon Pi Portal 1.0.18 API /api/V2/pp_udfv_admin endpoint, fails to perform necessary server-side validation. The... |
| CVE-2025-64064 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 /api/v2/pp_users endpoint fails to adequately check user permissions before processing a PATCH... |
| CVE-2025-34350 | HIGH | 8.7 | 0.9% | Nov 25, 2025 | UnForm Server versions < 10.1.15 contain an unauthenticated arbitrary file read and SMB coercion vulnerability in the Do... |
| CVE-2025-64066 | HIGH | 8.6 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 REST /api/v2/user/register endpoint suffers from a Broken Access Control vulnerability. The en... |
| CVE-2025-64062 | HIGH | 8.8 | 0.3% | Nov 25, 2025 | The Primakon Pi Portal 1.0.18 /api/V2/pp_users?email endpoint is used for user data filtering but lacks proper server-si... |
| CVE-2025-33205 | HIGH | 7.3 | 0.1% | Nov 25, 2025 | NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of func... |
| CVE-2025-33204 | HIGH | 7.8 | 0.2% | Nov 25, 2025 | NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data cre... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now