2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7719 | MEDIUM | 5.3 | 0.3% | Nov 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on... |
| CVE-2025-63785 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2... |
| CVE-2025-63784 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback... |
| CVE-2025-63687 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/... |
| CVE-2025-63686 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116... |
| CVE-2025-58465 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us... |
| CVE-2025-58463 | MEDIUM | 4.9 | 0.4% | Nov 7, 2025 | A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi... |
| CVE-2025-57712 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-57706 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user... |
| CVE-2025-54168 | MEDIUM | 4.8 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin... |
| CVE-2025-53413 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53412 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-53411 | MEDIUM | 4.9 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53410 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53409 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53408 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-52865 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-47207 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain... |
| CVE-2025-46413 | MEDIUM | 5.3 | 0.1% | Nov 7, 2025 | Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W... |
| CVE-2025-10966 | MEDIUM | 4.3 | 0.4% | Nov 7, 2025 | curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host... |
| CVE-2025-64346 | MEDIUM | 6 | 0.3% | Nov 7, 2025 | archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to fe... |
| CVE-2025-64339 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature i... |
| CVE-2025-12527 | MEDIUM | 4.3 | 0.2% | Nov 7, 2025 | The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili... |
| CVE-2025-12520 | MEDIUM | 4 | 0.2% | Nov 7, 2025 | The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ... |
| CVE-2025-64336 | MEDIUM | 5.4 | 0.3% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now