2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63783 | HIGH | 7.6 | 0.3% | Nov 7, 2025 | A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet... |
| CVE-2025-58469 | HIGH | 8.8 | 0.2% | Nov 7, 2025 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can the... |
| CVE-2025-58464 | HIGH | 7.5 | 0.4% | Nov 7, 2025 | A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit... |
| CVE-2025-54167 | HIGH | 7.2 | 0.4% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains a... |
| CVE-2025-12861 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the... |
| CVE-2025-12860 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. ... |
| CVE-2025-12859 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_... |
| CVE-2025-10968 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna... |
| CVE-2025-64343 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | (conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 ... |
| CVE-2025-4519 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala... |
| CVE-2025-64328 | HIGH | 7.2 | 84.4% | Nov 7, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov... |
| CVE-2025-64184 | HIGH | 8.8 | 0.4% | Nov 7, 2025 | Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constru... |
| CVE-2025-5483 | HIGH | 8.1 | 0.3% | Nov 7, 2025 | The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi... |
| CVE-2025-58423 | HIGH | 8.8 | 0.5% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-se... |
| CVE-2025-12636 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba... |
| CVE-2025-12036 | HIGH | 8.8 | 3.5% | Nov 6, 2025 | Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of b... |
| CVE-2025-11756 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised t... |
| CVE-2025-11460 | HIGH | 8.8 | 0.3% | Nov 6, 2025 | Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code vi... |
| CVE-2025-11458 | HIGH | 8.1 | 0.3% | Nov 6, 2025 | Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of boun... |
| CVE-2025-64178 | HIGH | 8.9 | 0.3% | Nov 6, 2025 | Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to dow... |
| CVE-2025-11211 | HIGH | 7.5 | 0.3% | Nov 6, 2025 | Out of bounds read in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out... |
| CVE-2025-11209 | HIGH | 8.2 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker to ... |
| CVE-2025-11206 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Heap buffer overflow in Video in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform a... |
| CVE-2025-11205 | HIGH | 8.8 | 0.3% | Nov 6, 2025 | Heap buffer overflow in WebGPU in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who had compromised the... |
| CVE-2025-64173 | HIGH | 7.5 | 0.3% | Nov 6, 2025 | Apollo Router Core is a configurable graph router written in Rust to run a federated supergraph using Apollo Federation ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now