2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63432 | MEDIUM | 4.6 | 0.1% | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fai... |
| CVE-2025-60917 | MEDIUM | 4.6 | 0.2% | Nov 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti... |
| CVE-2025-60916 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti... |
| CVE-2025-60914 | MEDIUM | 4.6 | 0.2% | Nov 24, 2025 | Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensit... |
| CVE-2025-60633 | MEDIUM | 6.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_Subs... |
| CVE-2025-60632 | MEDIUM | 6.5 | 0.2% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ... |
| CVE-2025-56423 | MEDIUM | 5.3 | 0.3% | Nov 24, 2025 | An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attac... |
| CVE-2025-10554 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERI... |
| CVE-2025-12978 | MEDIUM | 5.4 | 0.3% | Nov 24, 2025 | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fa... |
| CVE-2025-12972 | MEDIUM | 5.3 | 0.7% | Nov 24, 2025 | Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option i... |
| CVE-2025-12969 | MEDIUM | 6.5 | 0.6% | Nov 24, 2025 | Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain c... |
| CVE-2025-65503 | MEDIUM | 5.5 | 0.2% | Nov 24, 2025 | Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via... |
| CVE-2025-65502 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of s... |
| CVE-2025-65501 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of... |
| CVE-2025-65500 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65499 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause... |
| CVE-2025-65498 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65497 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65496 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-41017 | MEDIUM | 6.9 | 0.2% | Nov 24, 2025 | Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers... |
| CVE-2025-12628 | MEDIUM | 6.3 | 0.2% | Nov 24, 2025 | The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th... |
| CVE-2025-41087 | MEDIUM | 5.1 | 0.3% | Nov 24, 2025 | Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not pro... |
| CVE-2025-13588 | MEDIUM | 6.3 | 0.2% | Nov 24, 2025 | A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun... |
| CVE-2025-12569 | MEDIUM | 4.7 | 0.2% | Nov 24, 2025 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before ... |
| CVE-2025-12394 | MEDIUM | 5.9 | 0.3% | Nov 24, 2025 | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now