2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9479 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-13107 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform... |
| CVE-2025-13102 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote atta... |
| CVE-2025-13097 | MEDIUM | 5.4 | 0.1% | Nov 14, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentiall... |
| CVE-2025-64753 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document c... |
| CVE-2025-64752 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist instal... |
| CVE-2025-64749 | MEDIUM | 4.3 | 0.3% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messa... |
| CVE-2025-64748 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11... |
| CVE-2025-64747 | MEDIUM | 5.5 | 0.2% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vul... |
| CVE-2025-64746 | MEDIUM | 5.4 | 0.2% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Prior to version 11.13.0, Directus does... |
| CVE-2025-64745 | MEDIUM | 6.1 | 0.2% | Nov 13, 2025 | Astro is a web framework. Starting in version 5.2.0 and prior to version 5.15.6, a Reflected Cross-Site Scripting (XSS) ... |
| CVE-2025-4619 | MEDIUM | 6.6 | 0.5% | Nov 13, 2025 | A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reb... |
| CVE-2025-47222 | MEDIUM | 6.5 | 0.3% | Nov 13, 2025 | A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any... |
| CVE-2025-47221 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME... |
| CVE-2025-47220 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTO... |
| CVE-2025-60702 | MEDIUM | 6.5 | 2.3% | Nov 13, 2025 | A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `sys... |
| CVE-2025-60699 | MEDIUM | 6.5 | 0.8% | Nov 13, 2025 | A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `globa... |
| CVE-2025-55810 | MEDIUM | 6.8 | 0.2% | Nov 13, 2025 | A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmwa... |
| CVE-2025-46370 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Process Control vulnerability. A low pr... |
| CVE-2025-46368 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability... |
| CVE-2025-46362 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability.... |
| CVE-2025-60676 | MEDIUM | 6.5 | 3.5% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln... |
| CVE-2025-60675 | MEDIUM | 5.4 | 1.4% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the ti... |
| CVE-2025-60674 | MEDIUM | 6.8 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB... |
| CVE-2025-60673 | MEDIUM | 6.5 | 3.6% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now