2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64501 | HIGH | 7.6 | 0.2% | Nov 10, 2025 | ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be... |
| CVE-2025-64484 | HIGH | 8.5 | 0.6% | Nov 10, 2025 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat... |
| CVE-2025-64183 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64182 | HIGH | 7.8 | 0.2% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64181 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-63149 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list... |
| CVE-2025-12727 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exp... |
| CVE-2025-12726 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who ... |
| CVE-2025-12725 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an... |
| CVE-2025-12438 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to poten... |
| CVE-2025-12437 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng... |
| CVE-2025-12432 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via ... |
| CVE-2025-12430 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing... |
| CVE-2025-12429 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrar... |
| CVE-2025-12428 | HIGH | 8.8 | 6.8% | Nov 10, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write v... |
| CVE-2025-63288 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service. |
| CVE-2025-47286 | HIGH | 7.2 | 0.4% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by ... |
| CVE-2025-43723 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or ... |
| CVE-2025-12967 | HIGH | 8.6 | 0.4% | Nov 10, 2025 | An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low pr... |
| CVE-2025-63835 | HIGH | 8.8 | 0.6% | Nov 10, 2025 | A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in... |
| CVE-2025-63497 | HIGH | 7.1 | 0.2% | Nov 10, 2025 | The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System v... |
| CVE-2025-63457 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. Th... |
| CVE-2025-63456 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. ... |
| CVE-2025-63455 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus... |
| CVE-2025-63147 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlI... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now