2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13190 | HIGH | 8.8 | 0.7% | Nov 15, 2025 | A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the ... |
| CVE-2025-9317 | HIGH | 8.4 | 0.1% | Nov 15, 2025 | The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f... |
| CVE-2025-8386 | HIGH | 7.2 | 0.1% | Nov 15, 2025 | The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper w... |
| CVE-2025-64309 | HIGH | 7.4 | 0.2% | Nov 15, 2025 | The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut... |
| CVE-2025-64308 | HIGH | 7.1 | 0.2% | Nov 15, 2025 | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Bri... |
| CVE-2025-64307 | HIGH | 7.1 | 0.2% | Nov 15, 2025 | The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized... |
| CVE-2025-62765 | HIGH | 8.7 | 0.3% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a... |
| CVE-2025-59780 | HIGH | 8.7 | 0.3% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all... |
| CVE-2025-55034 | HIGH | 8.8 | 0.2% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow a... |
| CVE-2025-13187 | HIGH | 7.5 | 0.5% | Nov 14, 2025 | A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/si... |
| CVE-2025-63891 | HIGH | 7.5 | 0.4% | Nov 14, 2025 | Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote u... |
| CVE-2025-13185 | HIGH | 7.2 | 0.3% | Nov 14, 2025 | A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the fi... |
| CVE-2025-13033 | HIGH | 7.5 | 0.5% | Nov 14, 2025 | A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient em... |
| CVE-2025-63680 | HIGH | 8.6 | 0.3% | Nov 14, 2025 | Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination wi... |
| CVE-2025-13177 | HIGH | 8.8 | 0.2% | Nov 14, 2025 | A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulatio... |
| CVE-2025-54346 | HIGH | 7.6 | 0.2% | Nov 14, 2025 | A Reflected Cross Site Scripting (XSS) vulnerability was found in the Application Server of Desktop Alert PingAlert vers... |
| CVE-2025-54345 | HIGH | 7.5 | 0.3% | Nov 14, 2025 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Informati... |
| CVE-2025-13172 | HIGH | 8.8 | 0.2% | Nov 14, 2025 | A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ... |
| CVE-2025-13171 | HIGH | 8.8 | 0.3% | Nov 14, 2025 | A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such... |
| CVE-2025-13204 | HIGH | 7.3 | 0.4% | Nov 14, 2025 | npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use ... |
| CVE-2025-9982 | HIGH | 7.5 | 0.2% | Nov 14, 2025 | A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file a... |
| CVE-2025-11918 | HIGH | 7.3 | 0.1% | Nov 14, 2025 | Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the... |
| CVE-2025-8855 | HIGH | 8.1 | 0.3% | Nov 14, 2025 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio... |
| CVE-2025-55070 | HIGH | 7.5 | 0.3% | Nov 14, 2025 | Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticate... |
| CVE-2025-64444 | HIGH | 8.6 | 1.1% | Nov 14, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now