2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64329 | MEDIUM | 5.5 | 0.2% | Nov 7, 2025 | containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro... |
| CVE-2025-4522 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct ... |
| CVE-2025-64323 | MEDIUM | 5.3 | 0.2% | Nov 7, 2025 | kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack a... |
| CVE-2025-64187 | MEDIUM | 4.4 | 0.1% | Nov 7, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul... |
| CVE-2025-52662 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extra... |
| CVE-2025-48985 | MEDIUM | 5.3 | 0.2% | Nov 7, 2025 | A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have ... |
| CVE-2025-12789 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout p... |
| CVE-2025-64302 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing ... |
| CVE-2025-64179 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below,... |
| CVE-2025-64177 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, th... |
| CVE-2025-64176 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an... |
| CVE-2025-11216 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perf... |
| CVE-2025-11215 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds mem... |
| CVE-2025-11213 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who... |
| CVE-2025-11212 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who c... |
| CVE-2025-11210 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Side-channel information leakage in Tab in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced ... |
| CVE-2025-11208 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Media in Google Chrome prior to 141.0.7390.54 allowed a remote attacker who convinced a ... |
| CVE-2025-11207 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Side-channel information leakage in Storage in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform... |
| CVE-2025-64327 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. Versions 0.6.7 and below contai... |
| CVE-2025-64174 | MEDIUM | 4.8 | 0.2% | Nov 6, 2025 | Magento-lts is a long-term support alternative to Magento Community Edition (CE). Versions 20.15.0 and below are affecte... |
| CVE-2025-33110 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | IBM OpenPages 9.1, and 9.0 with Watson is vulnerable to HTML injection. A remote attacker could inject malicious HTML co... |
| CVE-2025-34247 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAc... |
| CVE-2025-34246 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.aja... |
| CVE-2025-34245 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsControl... |
| CVE-2025-34244 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDevic... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now