2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10907 | HIGH | 7.2 | 0.5% | Nov 5, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte... |
| CVE-2025-63248 | HIGH | 7.5 | 0.3% | Nov 5, 2025 | DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID... |
| CVE-2025-46364 | HIGH | 7.2 | 0.3% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI... |
| CVE-2025-45379 | HIGH | 8.4 | 0.7% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma... |
| CVE-2025-43990 | HIGH | 7.8 | 0.1% | Nov 5, 2025 | Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerabilit... |
| CVE-2025-30479 | HIGH | 7.2 | 1.1% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma... |
| CVE-2025-20376 | HIGH | 7.2 | 0.4% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a... |
| CVE-2025-20375 | HIGH | 7.2 | 0.3% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a... |
| CVE-2025-20343 | HIGH | 7.5 | 0.7% | Nov 5, 2025 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi... |
| CVE-2025-57130 | HIGH | 8.8 | 0.4% | Nov 5, 2025 | An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au... |
| CVE-2025-64458 | HIGH | 7.5 | 1.9% | Nov 5, 2025 | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s... |
| CVE-2025-61084 | HIGH | 7.1 | 0.2% | Nov 5, 2025 | MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h... |
| CVE-2025-46784 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouver... |
| CVE-2025-46705 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.... |
| CVE-2025-46404 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert La... |
| CVE-2025-3125 | HIGH | 7.2 | 0.8% | Nov 5, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp... |
| CVE-2025-12497 | HIGH | 8.1 | 0.5% | Nov 5, 2025 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version... |
| CVE-2025-10622 | HIGH | 8 | 0.5% | Nov 5, 2025 | A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set... |
| CVE-2025-64151 | HIGH | 8.4 | 0.1% | Nov 5, 2025 | Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A ... |
| CVE-2025-62225 | HIGH | 8.4 | 0.1% | Nov 5, 2025 | Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use... |
| CVE-2025-12384 | HIGH | 8.6 | 0.3% | Nov 5, 2025 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce... |
| CVE-2025-12139 | HIGH | 7.5 | 2.2% | Nov 5, 2025 | The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv... |
| CVE-2025-21079 | HIGH | 8.1 | 0.4% | Nov 5, 2025 | Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL ... |
| CVE-2025-21075 | HIGH | 7.5 | 0.2% | Nov 5, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b... |
| CVE-2025-21074 | HIGH | 7.5 | 0.2% | Nov 5, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now