2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65018 | HIGH | 7.1 | 0.2% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64720 | HIGH | 7.1 | 0.3% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-62155 | HIGH | 8.5 | 0.3% | Nov 25, 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2025-54563 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-54338 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-52538 | HIGH | 8 | 0.1% | Nov 24, 2025 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p... |
| CVE-2025-48510 | HIGH | 7.1 | 0.1% | Nov 24, 2025 | Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confi... |
| CVE-2025-36150 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-0003 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition poten... |
| CVE-2025-56400 | HIGH | 8.8 | 0.1% | Nov 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, a... |
| CVE-2025-52539 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced ... |
| CVE-2025-0005 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p... |
| CVE-2025-13609 | HIGH | 8.2 | 0.4% | Nov 24, 2025 | A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using ... |
| CVE-2025-63434 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downl... |
| CVE-2025-60915 | HIGH | 8.1 | 0.4% | Nov 24, 2025 | An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allo... |
| CVE-2025-60638 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ... |
| CVE-2025-56401 | HIGH | 7.6 | 0.2% | Nov 24, 2025 | ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName. |
| CVE-2025-44018 | HIGH | 8.3 | 0.2% | Nov 24, 2025 | A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft... |
| CVE-2025-40213 | HIGH | 7.8 | 0.2% | Nov 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set... |
| CVE-2025-10555 | HIGH | 8.7 | 0.2% | Nov 24, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer ... |
| CVE-2025-12970 | HIGH | 8.8 | 0.8% | Nov 24, 2025 | The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit... |
| CVE-2025-11921 | HIGH | 8.5 | 0.6% | Nov 24, 2025 | iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c... |
| CVE-2025-65998 | HIGH | 7.5 | 0.4% | Nov 24, 2025 | Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though ... |
| CVE-2025-65495 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t... |
| CVE-2025-65494 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now