2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63154 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urld... |
| CVE-2025-63153 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode... |
| CVE-2025-63152 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternPa... |
| CVE-2025-46430 | HIGH | 7.3 | 0.1% | Nov 10, 2025 | Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulne... |
| CVE-2025-63712 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete... |
| CVE-2025-63711 | HIGH | 7.1 | 0.2% | Nov 10, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an ... |
| CVE-2025-64685 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 missing TLS certificate validation enabled data disclosure |
| CVE-2025-64684 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | In JetBrains YouTrack before 2025.3.104432 information disclosure was possible via the feedback form |
| CVE-2025-64683 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | In JetBrains Hub before 2025.3.104432 information disclosure was possible via the Users API |
| CVE-2025-64457 | HIGH | 7 | 0.1% | Nov 10, 2025 | In JetBrains ReSharper, Rider and dotTrace before 2025.2.5 local privilege escalation was possible via race condition |
| CVE-2025-64456 | HIGH | 7.8 | 0.1% | Nov 10, 2025 | In JetBrains ReSharper before 2025.2.4 missing signature verification in DPA Collector allows local privilege escalation |
| CVE-2025-12405 | HIGH | 7.7 | 0.2% | Nov 10, 2025 | An improper privilege management vulnerability was found in Looker Studio. It impacted all JDBC-based connectors. A Loo... |
| CVE-2025-12409 | HIGH | 7.3 | 0.2% | Nov 10, 2025 | A SQL injection vulnerability was discovered in Looker Studio that allowed for data exfiltration from BigQuery data sour... |
| CVE-2025-12397 | HIGH | 7.6 | 0.3% | Nov 10, 2025 | A SQL injection vulnerability was found in Looker Studio. A Looker Studio user with report view access could inject mal... |
| CVE-2025-12155 | HIGH | 7.1 | 1.2% | Nov 10, 2025 | A Command Injection vulnerability, resulting from improper file path sanitization (Directory Traversal) in Looker allows... |
| CVE-2025-41731 | HIGH | 7.4 | 0.1% | Nov 10, 2025 | A vulnerability was identified in the password generation algorithm when accessing the debug-interface. An unauthenticat... |
| CVE-2025-62689 | HIGH | 8.7 | 0.4% | Nov 10, 2025 | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co... |
| CVE-2025-59777 | HIGH | 8.7 | 0.4% | Nov 10, 2025 | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co... |
| CVE-2025-12613 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing o... |
| CVE-2025-12867 | HIGH | 8.6 | 0.6% | Nov 10, 2025 | EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to u... |
| CVE-2025-12927 | HIGH | 7.2 | 0.3% | Nov 10, 2025 | A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the fi... |
| CVE-2025-12926 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function... |
| CVE-2025-12865 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to in... |
| CVE-2025-12864 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to in... |
| CVE-2025-12922 | HIGH | 8.8 | 0.5% | Nov 10, 2025 | A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now