2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20341 | HIGH | 8.8 | 0.5% | Nov 13, 2025 | A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv... |
| CVE-2025-13121 | HIGH | 7.3 | 0.3% | Nov 13, 2025 | A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a... |
| CVE-2025-64511 | HIGH | 8.8 | 0.2% | Nov 13, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv... |
| CVE-2025-64740 | HIGH | 7.8 | 0.1% | Nov 13, 2025 | Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an... |
| CVE-2025-64739 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure ... |
| CVE-2025-62483 | HIGH | 7.5 | 0.2% | Nov 13, 2025 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated use... |
| CVE-2025-12765 | HIGH | 7.4 | 0.2% | Nov 13, 2025 | pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver... |
| CVE-2025-12764 | HIGH | 7.5 | 0.4% | Nov 13, 2025 | pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker t... |
| CVE-2025-12763 | HIGH | 8.8 | 0.7% | Nov 13, 2025 | pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused ... |
| CVE-2025-12844 | HIGH | 7.1 | 0.4% | Nov 13, 2025 | The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,... |
| CVE-2025-12733 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe... |
| CVE-2025-11923 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati... |
| CVE-2025-64523 | HIGH | 8.8 | 0.4% | Nov 12, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-64500 | HIGH | 7.3 | 1.3% | Nov 12, 2025 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundati... |
| CVE-2025-40206 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefma... |
| CVE-2025-40205 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encod... |
| CVE-2025-40204 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: sctp: Fix MAC comparison to be constant-time To pr... |
| CVE-2025-40203 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace se... |
| CVE-2025-40202 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ipmi: Rework user message limit handling The limit... |
| CVE-2025-40201 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: kernel/sys.c: fix the racy usage of task_lock(tsk->... |
| CVE-2025-40199 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: page_pool: Fix PP_MAGIC_MASK to avoid crashing on s... |
| CVE-2025-40198 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid potential buffer over-read in parse_app... |
| CVE-2025-40190 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: ext4: guard against EA inode refcount underflow in ... |
| CVE-2025-40187 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: net/sctp: fix a null dereference in sctp_dispositio... |
| CVE-2025-40186 | HIGH | 8.1 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: tcp: Don't call reqsk_fastopen_remove() in tcp_conn... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now