2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-37735 | HIGH | 7 | 0.1% | Nov 6, 2025 | Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being ... |
| CVE-2025-11956 | HIGH | 8.9 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-9338 | HIGH | 7.3 | 0.1% | Nov 6, 2025 | A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability... |
| CVE-2025-64171 | HIGH | 8.7 | 0.2% | Nov 6, 2025 | MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n... |
| CVE-2025-55278 | HIGH | 8.1 | 0.2% | Nov 5, 2025 | Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep... |
| CVE-2025-12779 | HIGH | 8.8 | 0.2% | Nov 5, 2025 | Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,... |
| CVE-2025-63417 | HIGH | 7.2 | 0.2% | Nov 5, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authe... |
| CVE-2025-12745 | HIGH | 7.8 | 0.2% | Nov 5, 2025 | A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_a... |
| CVE-2025-11093 | HIGH | 7.2 | 0.4% | Nov 5, 2025 | An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal... |
| CVE-2025-10907 | HIGH | 7.2 | 0.5% | Nov 5, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte... |
| CVE-2025-63248 | HIGH | 7.5 | 0.3% | Nov 5, 2025 | DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID... |
| CVE-2025-46364 | HIGH | 7.2 | 0.3% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI... |
| CVE-2025-45379 | HIGH | 8.4 | 0.7% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma... |
| CVE-2025-43990 | HIGH | 7.8 | 0.1% | Nov 5, 2025 | Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerabilit... |
| CVE-2025-30479 | HIGH | 7.2 | 1.1% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma... |
| CVE-2025-20376 | HIGH | 7.2 | 0.4% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a... |
| CVE-2025-20375 | HIGH | 7.2 | 0.3% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a... |
| CVE-2025-20343 | HIGH | 7.5 | 0.7% | Nov 5, 2025 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi... |
| CVE-2025-57130 | HIGH | 8.8 | 0.4% | Nov 5, 2025 | An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au... |
| CVE-2025-64458 | HIGH | 7.5 | 1.9% | Nov 5, 2025 | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s... |
| CVE-2025-61084 | HIGH | 7.1 | 0.2% | Nov 5, 2025 | MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h... |
| CVE-2025-46784 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouver... |
| CVE-2025-46705 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.... |
| CVE-2025-46404 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert La... |
| CVE-2025-3125 | HIGH | 7.2 | 0.8% | Nov 5, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now