2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-46368 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability... |
| CVE-2025-46362 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain an Improper Access Control vulnerability.... |
| CVE-2025-60676 | MEDIUM | 6.5 | 3.5% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln... |
| CVE-2025-60675 | MEDIUM | 5.4 | 1.4% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the ti... |
| CVE-2025-60674 | MEDIUM | 6.8 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB... |
| CVE-2025-60673 | MEDIUM | 6.5 | 3.6% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln... |
| CVE-2025-60672 | MEDIUM | 6.5 | 3.7% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vuln... |
| CVE-2025-60701 | MEDIUM | 6.5 | 2.7% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-60700 | MEDIUM | 6.5 | 2.7% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-60693 | MEDIUM | 6.5 | 0.8% | Nov 13, 2025 | A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firm... |
| CVE-2025-60671 | MEDIUM | 5.4 | 1.3% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-823G router firmware DIR823G_V1.0.2B05_20181207.bin in the ti... |
| CVE-2025-59480 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, whic... |
| CVE-2025-12784 | MEDIUM | 4.9 | 0.3% | Nov 13, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering ... |
| CVE-2025-11777 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the A... |
| CVE-2025-60695 | MEDIUM | 5.9 | 0.2% | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032).... |
| CVE-2025-20355 | MEDIUM | 4.7 | 0.2% | Nov 13, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthen... |
| CVE-2025-20353 | MEDIUM | 6.1 | 0.2% | Nov 13, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote at... |
| CVE-2025-20346 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should... |
| CVE-2025-11538 | MEDIUM | 6.8 | 0.5% | Nov 13, 2025 | A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults ... |
| CVE-2025-64718 | MEDIUM | 5.3 | 0.4% | Nov 13, 2025 | js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to mod... |
| CVE-2025-64714 | MEDIUM | 5.8 | 0.4% | Nov 13, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior... |
| CVE-2025-64703 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations b... |
| CVE-2025-64525 | MEDIUM | 6.5 | 1.1% | Nov 13, 2025 | Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request ... |
| CVE-2025-60689 | MEDIUM | 5.4 | 8.5% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200... |
| CVE-2025-60688 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now