2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62372 | MEDIUM | 6.5 | 0.3% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can... |
| CVE-2025-62459 | MEDIUM | 6.1 | 0.3% | Nov 20, 2025 | Microsoft Defender Portal Spoofing Vulnerability |
| CVE-2025-13484 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe... |
| CVE-2025-36159 | MEDIUM | 5.5 | 0.1% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their ide... |
| CVE-2025-36158 | MEDIUM | 5.5 | 0.1% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from f... |
| CVE-2025-36153 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated atta... |
| CVE-2025-55124 | MEDIUM | 6.1 | 0.4% | Nov 20, 2025 | Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script. |
| CVE-2025-55123 | MEDIUM | 5.4 | 0.4% | Nov 20, 2025 | Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be a... |
| CVE-2025-52671 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes ... |
| CVE-2025-52670 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete... |
| CVE-2025-52669 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes no... |
| CVE-2025-52668 | MEDIUM | 5.4 | 0.4% | Nov 20, 2025 | Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier version... |
| CVE-2025-52667 | MEDIUM | 5.4 | 0.3% | Nov 20, 2025 | Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS... |
| CVE-2025-48987 | MEDIUM | 6.1 | 0.4% | Nov 20, 2025 | Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XS... |
| CVE-2025-35029 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authent... |
| CVE-2025-55128 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in th... |
| CVE-2025-55127 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the userna... |
| CVE-2025-55126 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box ... |
| CVE-2025-64524 | MEDIUM | 5.5 | 0.2% | Nov 20, 2025 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operati... |
| CVE-2025-64185 | MEDIUM | 6.9 | 0.2% | Nov 20, 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ... |
| CVE-2025-64027 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. ... |
| CVE-2025-63848 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code ... |
| CVE-2025-62724 | MEDIUM | 4.3 | 0.2% | Nov 20, 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time... |
| CVE-2025-13437 | MEDIUM | 5.6 | 0.1% | Nov 20, 2025 | When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_mo... |
| CVE-2025-62875 | MEDIUM | 5.5 | 0.2% | Nov 20, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now