2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12120 | HIGH | 7.3 | 0.3% | Nov 20, 2025 | Lite XL versions 2.1.8 and prior automatically execute the .lite_project.lua file when opening a project directory, with... |
| CVE-2025-62730 | HIGH | 8.8 | 0.3% | Nov 20, 2025 | SOPlanning is vulnerable to Privilege Escalation in user management tab. Users with user_manage_team role are allowed to... |
| CVE-2025-62294 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | SOPlanning is vulnerable to Predictable Generation of Password Recovery Token. Due to weak mechanism of generating recov... |
| CVE-2025-41075 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. Th... |
| CVE-2025-41074 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. ... |
| CVE-2025-40601 | HIGH | 7.5 | 1.1% | Nov 20, 2025 | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to ca... |
| CVE-2025-13468 | HIGH | 8.1 | 0.3% | Nov 20, 2025 | A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_fo... |
| CVE-2025-13435 | HIGH | 8.1 | 0.6% | Nov 20, 2025 | A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of ... |
| CVE-2025-13434 | HIGH | 7.5 | 0.4% | Nov 20, 2025 | A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file H... |
| CVE-2025-13433 | HIGH | 7.3 | 0.1% | Nov 20, 2025 | A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the... |
| CVE-2025-11676 | HIGH | 7.1 | 0.2% | Nov 20, 2025 | Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated... |
| CVE-2025-0645 | HIGH | 7.2 | 0.3% | Nov 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Lt... |
| CVE-2025-0643 | HIGH | 7.2 | 0.3% | Nov 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Comm... |
| CVE-2025-13423 | HIGH | 7.2 | 0.3% | Nov 20, 2025 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function ... |
| CVE-2025-11001 | HIGH | 7.8 | 27.0% | Nov 19, 2025 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-63719 | HIGH | 7.3 | 0.2% | Nov 19, 2025 | Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter use... |
| CVE-2025-63371 | HIGH | 7.5 | 0.6% | Nov 19, 2025 | Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file p... |
| CVE-2025-65103 | HIGH | 8.8 | 0.3% | Nov 19, 2025 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an ... |
| CVE-2025-63932 | HIGH | 7.3 | 6.4% | Nov 19, 2025 | D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary... |
| CVE-2025-51663 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based ... |
| CVE-2025-51661 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is co... |
| CVE-2025-65094 | HIGH | 8.8 | 0.3% | Nov 19, 2025 | WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their pr... |
| CVE-2025-65034 | HIGH | 8.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerabil... |
| CVE-2025-65033 | HIGH | 8.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma... |
| CVE-2025-65030 | HIGH | 7.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now