2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54345 | HIGH | 7.5 | 0.3% | Nov 14, 2025 | An issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. Sensitive Informati... |
| CVE-2025-13172 | HIGH | 8.8 | 0.2% | Nov 14, 2025 | A security flaw has been discovered in CodeAstro Gym Management System 1.0. Affected is an unknown function of the file ... |
| CVE-2025-13171 | HIGH | 8.8 | 0.3% | Nov 14, 2025 | A vulnerability was identified in ZZCMS 2023. This impacts an unknown function of the file /admin/wangkan_list.php. Such... |
| CVE-2025-13204 | HIGH | 7.3 | 0.4% | Nov 14, 2025 | npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use ... |
| CVE-2025-9982 | HIGH | 7.5 | 0.2% | Nov 14, 2025 | A vulnerability exists in QuickCMS version 6.8 where sensitive admin credentials are hardcoded in a configuration file a... |
| CVE-2025-11918 | HIGH | 7.3 | 0.1% | Nov 14, 2025 | Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the... |
| CVE-2025-8855 | HIGH | 8.1 | 0.3% | Nov 14, 2025 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio... |
| CVE-2025-55070 | HIGH | 7.5 | 0.3% | Nov 14, 2025 | Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticate... |
| CVE-2025-64444 | HIGH | 8.6 | 1.1% | Nov 14, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4... |
| CVE-2025-10686 | HIGH | 7.2 | 0.4% | Nov 14, 2025 | The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possib... |
| CVE-2025-13161 | HIGH | 7.5 | 0.5% | Nov 14, 2025 | IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo... |
| CVE-2025-12904 | HIGH | 7.2 | 0.2% | Nov 14, 2025 | The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA... |
| CVE-2025-64530 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions ... |
| CVE-2025-47913 | HIGH | 7.5 | 0.6% | Nov 13, 2025 | SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the cl... |
| CVE-2025-36096 | HIGH | 8.1 | 0.3% | Nov 13, 2025 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which... |
| CVE-2025-13131 | HIGH | 8.5 | 0.1% | Nov 13, 2025 | A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\... |
| CVE-2025-13130 | HIGH | 8.5 | 0.1% | Nov 13, 2025 | A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra... |
| CVE-2025-64726 | HIGH | 7.3 | 0.1% | Nov 13, 2025 | Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by... |
| CVE-2025-60679 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210... |
| CVE-2025-59840 | HIGH | 8.1 | 0.3% | Nov 13, 2025 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-46369 | HIGH | 7.8 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability... |
| CVE-2025-46367 | HIGH | 7.8 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Ac... |
| CVE-2025-63406 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitra... |
| CVE-2025-43515 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauth... |
| CVE-2025-64706 | HIGH | 7.5 | 0.2% | Nov 13, 2025 | Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Objec... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now