2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60672 | MEDIUM | 6.5 | 3.7% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln... |
| CVE-2025-60701 | MEDIUM | 6.5 | 2.7% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-60700 | MEDIUM | 6.5 | 2.7% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-60693 | MEDIUM | 6.5 | 0.8% | Nov 13, 2025 | A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firm... |
| CVE-2025-60671 | MEDIUM | 5.4 | 1.3% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the ti... |
| CVE-2025-59480 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, whic... |
| CVE-2025-12784 | MEDIUM | 4.9 | 0.3% | Nov 13, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering ... |
| CVE-2025-11777 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the A... |
| CVE-2025-60695 | MEDIUM | 5.9 | 0.2% | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032).... |
| CVE-2025-20355 | MEDIUM | 4.7 | 0.2% | Nov 13, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthen... |
| CVE-2025-20353 | MEDIUM | 6.1 | 0.2% | Nov 13, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote at... |
| CVE-2025-20346 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should... |
| CVE-2025-11538 | MEDIUM | 6.8 | 0.5% | Nov 13, 2025 | A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults ... |
| CVE-2025-64718 | MEDIUM | 5.3 | 0.4% | Nov 13, 2025 | js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to mod... |
| CVE-2025-64714 | MEDIUM | 5.8 | 0.4% | Nov 13, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior... |
| CVE-2025-64703 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations b... |
| CVE-2025-64525 | MEDIUM | 6.5 | 1.1% | Nov 13, 2025 | Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request ... |
| CVE-2025-60689 | MEDIUM | 5.4 | 8.5% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200... |
| CVE-2025-60688 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681... |
| CVE-2025-60687 | MEDIUM | 6.5 | 6.3% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B2023013... |
| CVE-2025-60686 | MEDIUM | 5.1 | 0.2% | Nov 13, 2025 | A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink router... |
| CVE-2025-60685 | MEDIUM | 5.1 | 0.2% | Nov 13, 2025 | A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (s... |
| CVE-2025-60684 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681... |
| CVE-2025-60683 | MEDIUM | 6.5 | 1.1% | Nov 13, 2025 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf... |
| CVE-2025-60682 | MEDIUM | 6.5 | 1.6% | Nov 13, 2025 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudup... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now