2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64185 | MEDIUM | 6.9 | 0.2% | Nov 20, 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ... |
| CVE-2025-64027 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. ... |
| CVE-2025-63848 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Stored cross site scripting (xss) vulnerability in SWISH prolog thru 2.2.0 allowing attackers to execute arbitrary code ... |
| CVE-2025-62724 | MEDIUM | 4.3 | 0.2% | Nov 20, 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, users can craft a "Time of Check to Time... |
| CVE-2025-13437 | MEDIUM | 5.6 | 0.1% | Nov 20, 2025 | When zx is invoked with --prefer-local=<path>, the CLI creates a symlink named ./node_modules pointing to <path>/node_mo... |
| CVE-2025-62875 | MEDIUM | 5.5 | 0.2% | Nov 20, 2025 | An Improper Check for Unusual or Exceptional Conditions vulnerability in OpenSMTPD allows local users to crash OpenSMTPD... |
| CVE-2025-62731 | MEDIUM | 4.8 | 0.1% | Nov 20, 2025 | SOPlanning is vulnerable to Stored XSS in /feries endpoint. Malicious attacker with access to public holidays feature is... |
| CVE-2025-62729 | MEDIUM | 5.4 | 0.1% | Nov 20, 2025 | SOPlanning is vulnerable to Stored XSS in /status endpoint. Malicious attacker with an account can inject arbitrary HTML... |
| CVE-2025-62297 | MEDIUM | 5.4 | 0.1% | Nov 20, 2025 | SOPlanning is vulnerable to Stored XSS in /projets endpoint. Malicious attacker with medium privileges can inject arbitr... |
| CVE-2025-62296 | MEDIUM | 5.4 | 0.1% | Nov 20, 2025 | SOPlanning is vulnerable to Stored XSS in /taches endpoint. Malicious attacker with medium privileges can inject arbitra... |
| CVE-2025-62295 | MEDIUM | 5.4 | 0.1% | Nov 20, 2025 | SOPlanning is vulnerable to Stored XSS in /groupe_form endpoint. Malicious attacker with medium privileges can inject ar... |
| CVE-2025-62293 | MEDIUM | 5.4 | 0.1% | Nov 20, 2025 | SOPlanning is vulnerable to Broken Access Control in /status endpoint. Due to lack of permission checks in Project Statu... |
| CVE-2025-60737 | MEDIUM | 6.1 | 0.3% | Nov 20, 2025 | Cross Site Scripting vulnerability in Ilevia EVE X1 Server Firmware Version<= 4.7.18.0.eden:Logic Version<=6.00 - 2025_0... |
| CVE-2025-36161 | MEDIUM | 5.9 | 0.2% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a remote attacker to obtain sensitive information, caused by the failure to ... |
| CVE-2025-65226 | MEDIUM | 4.3 | 0.2% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the deviceId parameter in /goform/saveParentControlInfo. |
| CVE-2025-65223 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the urls parameter of /goform/saveParentControlInfo. |
| CVE-2025-65222 | MEDIUM | 4.3 | 2.2% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg. |
| CVE-2025-65221 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList. |
| CVE-2025-65220 | MEDIUM | 4.3 | 0.2% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter. |
| CVE-2025-64984 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases pri... |
| CVE-2025-62346 | MEDIUM | 6.8 | 0.1% | Nov 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's we... |
| CVE-2025-60799 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The applicat... |
| CVE-2025-60798 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes ... |
| CVE-2025-60797 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application dire... |
| CVE-2025-60796 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. Us... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now