2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13785 | MEDIUM | 6.5 | 0.3% | Nov 30, 2025 | A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so... |
| CVE-2025-13784 | MEDIUM | 4.8 | 0.2% | Nov 30, 2025 | A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknow... |
| CVE-2025-66433 | MEDIUM | 4.2 | 0.1% | Nov 30, 2025 | HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by subm... |
| CVE-2025-66432 | MEDIUM | 5 | 0.2% | Nov 30, 2025 | In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date. |
| CVE-2025-66424 | MEDIUM | 6.5 | 0.2% | Nov 30, 2025 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40... |
| CVE-2025-66422 | MEDIUM | 4.3 | 0.2% | Nov 30, 2025 | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is ... |
| CVE-2025-66421 | MEDIUM | 5.4 | 0.1% | Nov 30, 2025 | Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.... |
| CVE-2025-66420 | MEDIUM | 5.4 | 0.1% | Nov 30, 2025 | Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and ... |
| CVE-2025-66291 | MEDIUM | 4.3 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r... |
| CVE-2025-66290 | MEDIUM | 4.3 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm... |
| CVE-2025-65892 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execut... |
| CVE-2025-65540 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. ... |
| CVE-2025-66221 | MEDIUM | 5.3 | 0.5% | Nov 29, 2025 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows p... |
| CVE-2025-61915 | MEDIUM | 6.7 | 0.4% | Nov 29, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.... |
| CVE-2025-58436 | MEDIUM | 5.5 | 0.2% | Nov 29, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.... |
| CVE-2025-53897 | MEDIUM | 6.8 | 0.2% | Nov 29, 2025 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an... |
| CVE-2025-66036 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cro... |
| CVE-2025-66027 | MEDIUM | 6.5 | 0.3% | Nov 29, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil... |
| CVE-2025-65113 | MEDIUM | 6.5 | 0.3% | Nov 29, 2025 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerabi... |
| CVE-2025-64715 | MEDIUM | 5.5 | 0.2% | Nov 29, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.... |
| CVE-2025-13683 | MEDIUM | 6.5 | 0.3% | Nov 28, 2025 | Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affec... |
| CVE-2025-59792 | MEDIUM | 5.3 | 0.3% | Nov 28, 2025 | Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks... |
| CVE-2025-59790 | MEDIUM | 5.4 | 0.4% | Nov 28, 2025 | Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v... |
| CVE-2025-51736 | MEDIUM | 6.3 | 0.2% | Nov 28, 2025 | File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-51734 | MEDIUM | 5.4 | 0.2% | Nov 28, 2025 | Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now