2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64442 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search fe... |
| CVE-2025-63544 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter. |
| CVE-2025-63543 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter. |
| CVE-2025-12902 | MEDIUM | 4.4 | 0.1% | Nov 7, 2025 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces... |
| CVE-2025-12896 | MEDIUM | 4.4 | 0.1% | Nov 7, 2025 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces... |
| CVE-2025-63640 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes ... |
| CVE-2025-63639 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting ... |
| CVE-2025-63638 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Descr... |
| CVE-2025-7700 | MEDIUM | 5.3 | 0.3% | Nov 7, 2025 | A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This ca... |
| CVE-2025-64432 | MEDIUM | 4.7 | 0.1% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed i... |
| CVE-2025-63717 | MEDIUM | 6.5 | 0.1% | Nov 7, 2025 | The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Softw... |
| CVE-2025-61261 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute a... |
| CVE-2025-36185 | MEDIUM | 5.5 | 0.1% | Nov 7, 2025 | IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to caus... |
| CVE-2025-36136 | MEDIUM | 5.5 | 0.1% | Nov 7, 2025 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes DB2 Connect Server) could... |
| CVE-2025-36135 | MEDIUM | 5.4 | 0.1% | Nov 7, 2025 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gatewa... |
| CVE-2025-36131 | MEDIUM | 4.6 | 0.2% | Nov 7, 2025 | IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ... |
| CVE-2025-36008 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2025-36006 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNI... |
| CVE-2025-12890 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | Improper handling of malformed Connection Request with the interval set to be 1 (which supposed to be illegal) and the ... |
| CVE-2025-63718 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | A SQL injection vulnerability exists in the SourceCodester PQMS (Patient Queue Management System) 1.0 in the api_patient... |
| CVE-2025-63716 | MEDIUM | 6.5 | 0.1% | Nov 7, 2025 | The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho... |
| CVE-2025-63714 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute... |
| CVE-2025-63713 | MEDIUM | 6.1 | 0.3% | Nov 7, 2025 | Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary... |
| CVE-2025-57697 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image... |
| CVE-2025-12829 | MEDIUM | 6.9 | 0.1% | Nov 7, 2025 | An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now