2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-2486 | HIGH | 8.8 | 0.1% | Nov 26, 2025 | The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, p... |
| CVE-2025-13084 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ... |
| CVE-2025-11461 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int... |
| CVE-2025-46175 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the au... |
| CVE-2025-56396 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi... |
| CVE-2025-46174 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the reset... |
| CVE-2025-45311 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary opera... |
| CVE-2025-13601 | HIGH | 7.7 | 0.3% | Nov 26, 2025 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_u... |
| CVE-2025-13735 | HIGH | 7.4 | 0.2% | Nov 26, 2025 | Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is... |
| CVE-2025-9558 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received... |
| CVE-2025-9557 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi... |
| CVE-2025-12061 | HIGH | 8.6 | 0.2% | Nov 26, 2025 | The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, a... |
| CVE-2025-64983 | HIGH | 8.6 | 0.3% | Nov 26, 2025 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac... |
| CVE-2025-66269 | HIGH | 7.1 | 0.1% | Nov 26, 2025 | The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all... |
| CVE-2025-66020 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i... |
| CVE-2025-66264 | HIGH | 7.2 | 0.1% | Nov 26, 2025 | The CMService.exe service runs with SYSTEM privileges and contains an unquoted service path. This allows a local attacke... |
| CVE-2025-66263 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Read via Null Byte Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66252 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Infinite Loop Denial of Service via Failed File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte... |
| CVE-2025-65957 | HIGH | 8.8 | 0.2% | Nov 26, 2025 | Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_... |
| CVE-2025-65952 | HIGH | 8.7 | 0.4% | Nov 25, 2025 | Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p... |
| CVE-2025-64713 | HIGH | 7.4 | 0.3% | Nov 25, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-... |
| CVE-2025-62703 | HIGH | 8.8 | 0.7% | Nov 25, 2025 | Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Da... |
| CVE-2025-51741 | HIGH | 7.5 | 0.4% | Nov 25, 2025 | An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to... |
| CVE-2025-9624 | HIGH | 7.5 | 0.5% | Nov 25, 2025 | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input... |
| CVE-2025-66017 | HIGH | 8.2 | 0.2% | Nov 25, 2025 | CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now