2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12875 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems... |
| CVE-2025-64431 | HIGH | 8.7 | 0.3% | Nov 7, 2025 | Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direc... |
| CVE-2025-36186 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations co... |
| CVE-2025-33012 | HIGH | 8.8 | 0.1% | Nov 7, 2025 | IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux coul... |
| CVE-2025-2534 | HIGH | 7.5 | 0.2% | Nov 7, 2025 | IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ... |
| CVE-2025-9458 | HIGH | 7.8 | 0.2% | Nov 7, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili... |
| CVE-2025-64430 | HIGH | 7.5 | 0.6% | Nov 7, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.... |
| CVE-2025-64347 | HIGH | 7.5 | 0.3% | Nov 7, 2025 | Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. ... |
| CVE-2025-57698 | HIGH | 7.5 | 0.7% | Nov 7, 2025 | AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the ... |
| CVE-2025-63783 | HIGH | 7.6 | 0.3% | Nov 7, 2025 | A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet... |
| CVE-2025-58469 | HIGH | 8.8 | 0.2% | Nov 7, 2025 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can the... |
| CVE-2025-58464 | HIGH | 7.5 | 0.4% | Nov 7, 2025 | A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit... |
| CVE-2025-54167 | HIGH | 7.2 | 0.4% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains a... |
| CVE-2025-12861 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the... |
| CVE-2025-12860 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. ... |
| CVE-2025-12859 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_... |
| CVE-2025-10968 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna... |
| CVE-2025-64343 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | (conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 ... |
| CVE-2025-4519 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala... |
| CVE-2025-64328 | HIGH | 7.2 | 84.4% | Nov 7, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov... |
| CVE-2025-64184 | HIGH | 8.8 | 0.4% | Nov 7, 2025 | Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constru... |
| CVE-2025-5483 | HIGH | 8.1 | 0.3% | Nov 7, 2025 | The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi... |
| CVE-2025-58423 | HIGH | 8.8 | 0.5% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-se... |
| CVE-2025-12636 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba... |
| CVE-2025-12036 | HIGH | 8.8 | 3.7% | Nov 6, 2025 | Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now