2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40183 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix metadata_dst leak __bpf_redirect_neigh_v{4... |
| CVE-2025-40182 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: crypto: skcipher - Fix reqsize handling Commit afd... |
| CVE-2025-46608 | HIGH | 7.2 | 0.4% | Nov 12, 2025 | Dell Data Lakehouse, versions prior to 1.6.0.0, contain(s) an Improper Access Control vulnerability. A high privileged a... |
| CVE-2025-13063 | HIGH | 7.3 | 0.3% | Nov 12, 2025 | A flaw has been found in DinukaNavaratna Dee Store 1.0. Affected is an unknown function. Executing manipulation can lead... |
| CVE-2025-13061 | HIGH | 8.8 | 0.3% | Nov 12, 2025 | A vulnerability was detected in itsourcecode Online Voting System 1.0. This impacts an unknown function of the file /ind... |
| CVE-2025-8485 | HIGH | 7.3 | 0.1% | Nov 12, 2025 | An improper permissions vulnerability was reported in Lenovo App Store that could allow a local authenticated user to ex... |
| CVE-2025-46428 | HIGH | 8.8 | 1.1% | Nov 12, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used... |
| CVE-2025-46427 | HIGH | 8.8 | 1.1% | Nov 12, 2025 | Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Neutralization of Special Elements used ... |
| CVE-2025-12048 | HIGH | 7.7 | 0.2% | Nov 12, 2025 | An arbitrary file upload vulnerability was reported in the Lenovo Scanner Pro client during an internal security assessm... |
| CVE-2025-10495 | HIGH | 7.7 | 0.2% | Nov 12, 2025 | A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zon... |
| CVE-2025-64099 | HIGH | 8.1 | 0.3% | Nov 12, 2025 | Open Access Management (OpenAM) is an access management solution. In versions prior to 16.0.0, if the "claims_parameter_... |
| CVE-2025-63929 | HIGH | 7.5 | 0.3% | Nov 12, 2025 | A null pointer dereference vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). When multiple thr... |
| CVE-2025-63679 | HIGH | 7.5 | 0.3% | Nov 12, 2025 | free5gc v4.1.0 and before is vulnerable to Buffer Overflow. When AMF receives an UplinkRANConfigurationTransfer NGAP mes... |
| CVE-2025-61667 | HIGH | 7 | 0.1% | Nov 12, 2025 | The Datadog Agent collects events and metrics from hosts and sends them to Datadog. A vulnerability within the Datadog L... |
| CVE-2025-57310 | HIGH | 8.8 | 0.2% | Nov 12, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in Salmen2/Simple-Faucet-Script v1.07 via crafted POST request to admi... |
| CVE-2025-65002 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | Fujitsu / Fsas Technologies iRMC S6 on M5 before 1.37S mishandles Redfish/WebUI access if the length of a username is ex... |
| CVE-2025-65001 | HIGH | 8.2 | 0.1% | Nov 12, 2025 | Fujitsu fbiosdrv.sys before 2.5.0.0 allows an attacker to potentially affect system confidentiality, integrity, and avai... |
| CVE-2025-63811 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | An issue was discovered in dvsekhvalnov jose2go 1.5.0 thru 1.7.0 allowing an attacker to cause a Denial-of-Service (DoS)... |
| CVE-2025-59088 | HIGH | 8.6 | 0.4% | Nov 12, 2025 | If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default... |
| CVE-2025-2843 | HIGH | 8.8 | 0.3% | Nov 12, 2025 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment... |
| CVE-2025-13042 | HIGH | 8.8 | 0.2% | Nov 12, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exp... |
| CVE-2025-11797 | HIGH | 7.8 | 0.1% | Nov 12, 2025 | A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malici... |
| CVE-2025-11795 | HIGH | 7.8 | 0.1% | Nov 12, 2025 | A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ... |
| CVE-2025-64293 | HIGH | 7.6 | 0.2% | Nov 12, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Anal... |
| CVE-2025-11700 | HIGH | 7.5 | 31.0% | Nov 12, 2025 | N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now