2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12003 | HIGH | 8.2 | 0.6% | Nov 25, 2025 | A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact... |
| CVE-2025-13644 | HIGH | 7.5 | 0.3% | Nov 25, 2025 | MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue a... |
| CVE-2025-12742 | HIGH | 7.5 | 0.2% | Nov 25, 2025 | A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Ter... |
| CVE-2025-13507 | HIGH | 7.1 | 0.2% | Nov 25, 2025 | Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON doc... |
| CVE-2025-13068 | HIGH | 7.2 | 0.2% | Nov 25, 2025 | The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i... |
| CVE-2025-59373 | HIGH | 8.5 | 0.1% | Nov 25, 2025 | A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can... |
| CVE-2025-9803 | HIGH | 8.8 | 0.4% | Nov 25, 2025 | lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth ... |
| CVE-2025-65951 | HIGH | 8.7 | 0.1% | Nov 25, 2025 | Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim... |
| CVE-2025-64761 | HIGH | 7.2 | 0.3% | Nov 25, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could ... |
| CVE-2025-65018 | HIGH | 7.1 | 0.2% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64720 | HIGH | 7.1 | 0.3% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-62155 | HIGH | 8.5 | 0.3% | Nov 25, 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2025-54563 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-54338 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-52538 | HIGH | 8 | 0.1% | Nov 24, 2025 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p... |
| CVE-2025-48510 | HIGH | 7.1 | 0.1% | Nov 24, 2025 | Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confi... |
| CVE-2025-36150 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-0003 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition poten... |
| CVE-2025-56400 | HIGH | 8.8 | 0.1% | Nov 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, a... |
| CVE-2025-52539 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced ... |
| CVE-2025-0005 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p... |
| CVE-2025-13609 | HIGH | 8.2 | 0.4% | Nov 24, 2025 | A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using ... |
| CVE-2025-63434 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downl... |
| CVE-2025-60915 | HIGH | 8.1 | 0.4% | Nov 24, 2025 | An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allo... |
| CVE-2025-60638 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now