2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-56401 | HIGH | 7.6 | 0.2% | Nov 24, 2025 | ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName. |
| CVE-2025-44018 | HIGH | 8.3 | 0.2% | Nov 24, 2025 | A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft... |
| CVE-2025-40213 | HIGH | 7.8 | 0.2% | Nov 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set... |
| CVE-2025-10555 | HIGH | 8.7 | 0.2% | Nov 24, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer ... |
| CVE-2025-12970 | HIGH | 8.8 | 0.8% | Nov 24, 2025 | The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit... |
| CVE-2025-11921 | HIGH | 8.5 | 0.6% | Nov 24, 2025 | iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c... |
| CVE-2025-65998 | HIGH | 7.5 | 0.4% | Nov 24, 2025 | Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though ... |
| CVE-2025-65495 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t... |
| CVE-2025-65494 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker... |
| CVE-2025-65493 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servic... |
| CVE-2025-41016 | HIGH | 8.7 | 0.2% | Nov 24, 2025 | Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images... |
| CVE-2025-41729 | HIGH | 7.5 | 0.4% | Nov 24, 2025 | An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denia... |
| CVE-2025-12741 | HIGH | 7.7 | 0.2% | Nov 24, 2025 | A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, ca... |
| CVE-2025-12740 | HIGH | 7.7 | 0.2% | Nov 24, 2025 | A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML,... |
| CVE-2025-12739 | HIGH | 7.3 | 0.3% | Nov 24, 2025 | An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would exe... |
| CVE-2025-13586 | HIGH | 7.2 | 0.3% | Nov 24, 2025 | A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file... |
| CVE-2025-12629 | HIGH | 7.1 | 0.1% | Nov 24, 2025 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2025-7402 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In... |
| CVE-2025-13581 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-13580 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.ph... |
| CVE-2025-13579 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php.... |
| CVE-2025-13576 | HIGH | 8.8 | 0.2% | Nov 24, 2025 | A vulnerability was detected in code-projects Blog Site 1.0. The affected element is an unknown function of the file /ad... |
| CVE-2025-13575 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A security vulnerability has been detected in code-projects Blog Site 1.0. Impacted is the function category_exists of t... |
| CVE-2025-13574 | HIGH | 7.2 | 0.3% | Nov 24, 2025 | A weakness has been identified in code-projects Online Bidding System 1.0. This issue affects the function categoryadd o... |
| CVE-2025-13573 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A security flaw has been discovered in projectworlds can pass malicious payloads up to 1.0. This vulnerability affects u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now