2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-51733 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-11156 | MEDIUM | 5.9 | 0.1% | Nov 28, 2025 | Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex... |
| CVE-2025-12143 | MEDIUM | 6.9 | 0.2% | Nov 28, 2025 | Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33. |
| CVE-2025-66386 | MEDIUM | 4.1 | 0.3% | Nov 28, 2025 | app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin. |
| CVE-2025-66382 | MEDIUM | 5.5 | 0.2% | Nov 28, 2025 | In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing ... |
| CVE-2025-66371 | MEDIUM | 5 | 0.3% | Nov 28, 2025 | Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XM... |
| CVE-2025-66370 | MEDIUM | 5 | 0.3% | Nov 28, 2025 | Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to... |
| CVE-2025-58305 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m... |
| CVE-2025-58304 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma... |
| CVE-2025-58302 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2025-13737 | MEDIUM | 4.3 | 0.1% | Nov 28, 2025 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2025-64314 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-64313 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a... |
| CVE-2025-64311 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect... |
| CVE-2025-58316 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2025-58315 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2025-58312 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2025-58310 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may... |
| CVE-2025-58307 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-58303 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-58294 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2025-66361 | MEDIUM | 6.5 | 0.2% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p... |
| CVE-2025-66359 | MEDIUM | 6.1 | 0.2% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl... |
| CVE-2025-12559 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em... |
| CVE-2025-13765 | MEDIUM | 4.3 | 0.3% | Nov 27, 2025 | Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now