2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60698 | HIGH | 7.3 | 3.4% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-60697 | HIGH | 7.3 | 3.3% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-12785 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering ... |
| CVE-2025-60696 | HIGH | 8.4 | 0.2% | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_... |
| CVE-2025-60694 | HIGH | 7.5 | 1.3% | Nov 13, 2025 | A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 route... |
| CVE-2025-60692 | HIGH | 8.4 | 0.2% | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmwa... |
| CVE-2025-60691 | HIGH | 8.8 | 0.7% | Nov 13, 2025 | A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.... |
| CVE-2025-60690 | HIGH | 8.8 | 4.4% | Nov 13, 2025 | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F... |
| CVE-2025-20349 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitr... |
| CVE-2025-20341 | HIGH | 8.8 | 0.5% | Nov 13, 2025 | A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv... |
| CVE-2025-13121 | HIGH | 7.3 | 0.3% | Nov 13, 2025 | A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a... |
| CVE-2025-64511 | HIGH | 8.8 | 0.2% | Nov 13, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv... |
| CVE-2025-64740 | HIGH | 7.8 | 0.1% | Nov 13, 2025 | Improper verification of cryptographic signature in the installer for Zoom Workplace VDI Client for Windows may allow an... |
| CVE-2025-64739 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure ... |
| CVE-2025-62483 | HIGH | 7.5 | 0.2% | Nov 13, 2025 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated use... |
| CVE-2025-12765 | HIGH | 7.4 | 0.2% | Nov 13, 2025 | pgAdmin <= 9.9 is affected by a vulnerability in the LDAP authentication mechanism allows bypassing TLS certificate ver... |
| CVE-2025-12764 | HIGH | 7.5 | 0.4% | Nov 13, 2025 | pgAdmin <= 9.9 is affected by an LDAP injection vulnerability in the LDAP authentication flow that allows an attacker t... |
| CVE-2025-12763 | HIGH | 8.8 | 0.7% | Nov 13, 2025 | pgAdmin 4 versions up to 9.9 are affected by a command injection vulnerability on Windows systems. This issue is caused ... |
| CVE-2025-12844 | HIGH | 7.1 | 0.4% | Nov 13, 2025 | The AI Engine plugin for WordPress is vulnerable to PHP Object Injection via PHAR Deserialization in all versions up to,... |
| CVE-2025-12733 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | The Import any XML, CSV or Excel File to WordPress (WP All Import) plugin for WordPress is vulnerable to Remote Code Exe... |
| CVE-2025-11923 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to privilege escalati... |
| CVE-2025-64523 | HIGH | 8.8 | 0.4% | Nov 12, 2025 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, previ... |
| CVE-2025-64500 | HIGH | 7.3 | 1.3% | Nov 12, 2025 | Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Symfony's HttpFoundati... |
| CVE-2025-40206 | HIGH | 7.8 | 0.1% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_objref: validate objref and objrefma... |
| CVE-2025-40205 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: avoid potential out-of-bounds in btrfs_encod... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now