2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55796 | HIGH | 7.5 | 0.5% | Nov 18, 2025 | The openml/openml.org web application version v2.0.20241110 uses predictable MD5-based tokens for critical user workflow... |
| CVE-2025-53843 | HIGH | 7.5 | 0.6% | Nov 18, 2025 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO... |
| CVE-2025-47761 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7... |
| CVE-2025-46776 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 t... |
| CVE-2025-46373 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, F... |
| CVE-2025-34324 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | GoSign Desktop versions 2.4.0 and earlier use an unsigned update manifest for distributing application updates. The mani... |
| CVE-2025-33184 | HIGH | 7.8 | 0.4% | Nov 18, 2025 | NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod... |
| CVE-2025-33183 | HIGH | 7.8 | 0.4% | Nov 18, 2025 | NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a cod... |
| CVE-2025-63800 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty s... |
| CVE-2025-63602 | HIGH | 7.3 | 0.2% | Nov 18, 2025 | A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MS... |
| CVE-2025-63408 | HIGH | 7.8 | 0.3% | Nov 18, 2025 | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacke... |
| CVE-2025-12383 | HIGH | 7.4 | 0.3% | Nov 18, 2025 | In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such... |
| CVE-2025-59113 | HIGH | 7.5 | 0.2% | Nov 18, 2025 | Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt co... |
| CVE-2025-13347 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | A flaw has been found in SourceCodester Train Station Ticketing System 1.0. This vulnerability affects unknown code of t... |
| CVE-2025-13346 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | A vulnerability was detected in SourceCodester Train Station Ticketing System 1.0. This affects an unknown part of the f... |
| CVE-2025-6670 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method... |
| CVE-2025-13345 | HIGH | 8.8 | 0.4% | Nov 18, 2025 | A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue ... |
| CVE-2025-41737 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules. |
| CVE-2025-41736 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th... |
| CVE-2025-41735 | HIGH | 8.8 | 0.5% | Nov 18, 2025 | A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem... |
| CVE-2025-4212 | HIGH | 7.2 | 0.2% | Nov 18, 2025 | The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl... |
| CVE-2025-13069 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, ... |
| CVE-2025-12955 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions ... |
| CVE-2025-13088 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up ... |
| CVE-2025-12775 | HIGH | 8.8 | 0.5% | Nov 18, 2025 | The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now