2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13226 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-36553 | HIGH | 8.8 | 0.2% | Nov 17, 2025 | A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell... |
| CVE-2025-36463 | HIGH | 7.3 | 0.1% | Nov 17, 2025 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun... |
| CVE-2025-36462 | HIGH | 7.3 | 0.1% | Nov 17, 2025 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun... |
| CVE-2025-36461 | HIGH | 7.3 | 0.1% | Nov 17, 2025 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun... |
| CVE-2025-36460 | HIGH | 7.3 | 0.1% | Nov 17, 2025 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter fun... |
| CVE-2025-32089 | HIGH | 8.8 | 0.2% | Nov 17, 2025 | A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and ... |
| CVE-2025-31649 | HIGH | 8.7 | 0.2% | Nov 17, 2025 | A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to ... |
| CVE-2025-31361 | HIGH | 8.7 | 0.2% | Nov 17, 2025 | A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell Co... |
| CVE-2025-13304 | HIGH | 8.8 | 0.7% | Nov 17, 2025 | A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This v... |
| CVE-2025-13224 | HIGH | 8.8 | 0.4% | Nov 17, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-13223 | HIGH | 8.8 | 4.8% | Nov 17, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-36118 | HIGH | 7.5 | 0.3% | Nov 17, 2025 | IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive informati... |
| CVE-2025-36357 | HIGH | 8 | 0.7% | Nov 17, 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the... |
| CVE-2025-64756 | HIGH | 7.5 | 3.0% | Nov 17, 2025 | Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, th... |
| CVE-2025-58407 | HIGH | 7.4 | 0.2% | Nov 17, 2025 | Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU rac... |
| CVE-2025-55057 | HIGH | 8.8 | 0.1% | Nov 17, 2025 | Multiple CWE-352 Cross-Site Request Forgery (CSRF) |
| CVE-2025-34323 | HIGH | 7.8 | 0.3% | Nov 17, 2025 | Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo... |
| CVE-2025-34322 | HIGH | 7.2 | 4.6% | Nov 17, 2025 | Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen... |
| CVE-2025-63917 | HIGH | 7.1 | 0.3% | Nov 17, 2025 | PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) re... |
| CVE-2025-62519 | HIGH | 7.2 | 0.7% | Nov 17, 2025 | phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in... |
| CVE-2025-58410 | HIGH | 7.5 | 0.2% | Nov 17, 2025 | Software installed and run as a non-privileged user may conduct improper GPU system calls to gain write permissions to m... |
| CVE-2025-13319 | HIGH | 8.8 | 0.4% | Nov 17, 2025 | An injection vulnerability has been discovered in the API feature in Digi On-Prem Manager, enabling an attacker with val... |
| CVE-2025-13290 | HIGH | 8.8 | 0.3% | Nov 17, 2025 | A vulnerability has been found in code-projects Simple Food Ordering System 1.0. Affected by this issue is some unknown ... |
| CVE-2025-63916 | HIGH | 8.1 | 1.4% | Nov 17, 2025 | MyScreenTools v2.2.1.0 contains a critical OS command injection vulnerability in the GIF compression tool. The applicati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now