2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64522 | HIGH | 7.6 | 0.3% | Nov 10, 2025 | Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where ... |
| CVE-2025-64519 | HIGH | 8.8 | 0.4% | Nov 10, 2025 | TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including ... |
| CVE-2025-63678 | HIGH | 7.2 | 0.4% | Nov 10, 2025 | An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage... |
| CVE-2025-11578 | HIGH | 7.2 | 0.6% | Nov 10, 2025 | A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise... |
| CVE-2025-64518 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida... |
| CVE-2025-64512 | HIGH | 7.8 | 0.3% | Nov 10, 2025 | Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documen... |
| CVE-2025-64509 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope... |
| CVE-2025-64508 | HIGH | 7.5 | 0.4% | Nov 10, 2025 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli strea... |
| CVE-2025-64507 | HIGH | 7.8 | 0.1% | Nov 10, 2025 | Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu... |
| CVE-2025-64501 | HIGH | 7.6 | 0.2% | Nov 10, 2025 | ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be... |
| CVE-2025-64484 | HIGH | 8.5 | 0.6% | Nov 10, 2025 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat... |
| CVE-2025-64183 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64182 | HIGH | 7.8 | 0.2% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64181 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-63149 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list... |
| CVE-2025-12727 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exp... |
| CVE-2025-12726 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | Inappropriate implementation in Views in Google Chrome on Windows prior to 142.0.7444.137 allowed a remote attacker who ... |
| CVE-2025-12725 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Out of bounds read in WebGPU in Google Chrome on Android prior to 142.0.7444.137 allowed a remote attacker to perform an... |
| CVE-2025-12438 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to poten... |
| CVE-2025-12437 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | Use after free in PageInfo in Google Chrome prior to 142.0.7444.59 allowed a remote attacker who convinced a user to eng... |
| CVE-2025-12432 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Race in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via ... |
| CVE-2025-12430 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Object lifecycle issue in Media in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform UI spoofing... |
| CVE-2025-12429 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrar... |
| CVE-2025-12428 | HIGH | 8.8 | 6.6% | Nov 10, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write v... |
| CVE-2025-63288 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now