2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13807 | MEDIUM | 4.3 | 0.4% | Dec 1, 2025 | A vulnerability was detected in orionsec orion-ops up to 5925824997a3109651bbde07460958a7be249ed1. Affected is the funct... |
| CVE-2025-13804 | MEDIUM | 4.3 | 0.3% | Dec 1, 2025 | A security flaw has been discovered in nutzam NutzBoot up to 2.6.0-SNAPSHOT. The impacted element is an unknown function... |
| CVE-2025-13802 | MEDIUM | 4.3 | 0.3% | Dec 1, 2025 | A vulnerability was determined in jairiidriss RestaurantWebsite up to e7911f12d035e8e2f9a75e7a28b59e4ef5c1d654. Impacted... |
| CVE-2025-13796 | MEDIUM | 6.3 | 0.3% | Dec 1, 2025 | A security vulnerability has been detected in deco-cx apps up to 0.120.1. Affected by this vulnerability is the function... |
| CVE-2025-13793 | MEDIUM | 4.3 | 0.3% | Nov 30, 2025 | A weakness has been identified in winston-dsouza Ecommerce-Website up to 87734c043269baac0b4cfe9664784462138b1b2e. Affec... |
| CVE-2025-13791 | MEDIUM | 6.5 | 0.5% | Nov 30, 2025 | A vulnerability was identified in Scada-LTS up to 2.7.8.1. Affected is the function Common.getHomeDir of the file br/org... |
| CVE-2025-13789 | MEDIUM | 5.3 | 0.3% | Nov 30, 2025 | A vulnerability was found in ZenTao up to 21.7.6-8564. This affects the function makeRequest of the file module/ai/model... |
| CVE-2025-13785 | MEDIUM | 6.5 | 0.4% | Nov 30, 2025 | A security vulnerability has been detected in yungifez Skuul School Management System up to 2.6.5. This issue affects so... |
| CVE-2025-13784 | MEDIUM | 4.8 | 0.3% | Nov 30, 2025 | A weakness has been identified in yungifez Skuul School Management System up to 2.6.5. This vulnerability affects unknow... |
| CVE-2025-66433 | MEDIUM | 4.2 | 0.1% | Nov 30, 2025 | HTCondor Access Point before 25.3.1 allows an authenticated user to impersonate other users on the local machine by subm... |
| CVE-2025-66432 | MEDIUM | 5 | 0.2% | Nov 30, 2025 | In Oxide control plane 15 through 17 before 17.1, API tokens can be renewed past their expiration date. |
| CVE-2025-66424 | MEDIUM | 6.5 | 0.2% | Nov 30, 2025 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40... |
| CVE-2025-66422 | MEDIUM | 4.3 | 0.2% | Nov 30, 2025 | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is ... |
| CVE-2025-66421 | MEDIUM | 5.4 | 0.1% | Nov 30, 2025 | Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.... |
| CVE-2025-66420 | MEDIUM | 5.4 | 0.1% | Nov 30, 2025 | Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and ... |
| CVE-2025-66291 | MEDIUM | 4.3 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r... |
| CVE-2025-66290 | MEDIUM | 4.3 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm... |
| CVE-2025-65892 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execut... |
| CVE-2025-65540 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. ... |
| CVE-2025-66221 | MEDIUM | 5.3 | 0.5% | Nov 29, 2025 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows p... |
| CVE-2025-61915 | MEDIUM | 6.7 | 0.4% | Nov 29, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.... |
| CVE-2025-58436 | MEDIUM | 5.5 | 0.2% | Nov 29, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.... |
| CVE-2025-53897 | MEDIUM | 6.8 | 0.2% | Nov 29, 2025 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an... |
| CVE-2025-66036 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cro... |
| CVE-2025-66027 | MEDIUM | 6.5 | 0.3% | Nov 29, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now