2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66265 | MEDIUM | 6.9 | 0.1% | Nov 26, 2025 | CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a... |
| CVE-2025-66260 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | PostgreSQL SQL Injection (status_sql.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions 30, ... |
| CVE-2025-66258 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross-Site Scripting via XML Injection in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitter versions ... |
| CVE-2025-66019 | MEDIUM | 6.6 | 0.3% | Nov 26, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability... |
| CVE-2025-65963 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient... |
| CVE-2025-65956 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t... |
| CVE-2025-65953 | MEDIUM | 6 | 0.2% | Nov 25, 2025 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA... |
| CVE-2025-64704 | MEDIUM | 5.5 | 0.2% | Nov 25, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is... |
| CVE-2025-63735 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the th... |
| CVE-2025-21621 | MEDIUM | 6.1 | 0.3% | Nov 25, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a refle... |
| CVE-2025-65647 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows info... |
| CVE-2025-65961 | MEDIUM | 4.8 | 0.1% | Nov 25, 2025 | Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, it is possible to i... |
| CVE-2025-65960 | MEDIUM | 6.6 | 0.2% | Nov 25, 2025 | Contao is an Open Source CMS. From version 4.0.0 to before 4.13.57, before 5.3.42, and before 5.6.5, back end users with... |
| CVE-2025-64067 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 API endpoints responsible for retrieving object-specific or filtered data (e.g., user profiles... |
| CVE-2025-61167 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | SIGB PMB v8.0.1.14 was discovered to contain multiple SQL injection vulnerabilities in the /opac_css/ajax_selector.php c... |
| CVE-2025-33197 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a NULL pointer dereferen... |
| CVE-2025-33196 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause a resource to be reused.... |
| CVE-2025-33193 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause improper validation of i... |
| CVE-2025-33192 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read... |
| CVE-2025-33191 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read.... |
| CVE-2025-64061 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access con... |
| CVE-2025-64049 | MEDIUM | 4.8 | 0.3% | Nov 25, 2025 | A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote ... |
| CVE-2025-13467 | MEDIUM | 5.5 | 0.4% | Nov 25, 2025 | A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm adminis... |
| CVE-2025-59485 | MEDIUM | 4.8 | 0.1% | Nov 25, 2025 | Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili... |
| CVE-2025-59372 | MEDIUM | 6.9 | 0.6% | Nov 25, 2025 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now