2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34243 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetwo... |
| CVE-2025-34242 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxActio... |
| CVE-2025-34241 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDevice... |
| CVE-2025-34240 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgr... |
| CVE-2025-34238 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsControlle... |
| CVE-2025-34237 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via Standalone... |
| CVE-2025-34236 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksCo... |
| CVE-2025-22397 | MEDIUM | 4.9 | 0.4% | Nov 6, 2025 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 thro... |
| CVE-2025-12815 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS ... |
| CVE-2025-12808 | MEDIUM | 6.5 | 0.4% | Nov 6, 2025 | Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as ... |
| CVE-2025-62950 | MEDIUM | 4.3 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-g... |
| CVE-2025-62914 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in anibalwainstein Effect Maker effect-maker allows Exploiting Incorrectly Configure... |
| CVE-2025-62051 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AndonDesign UDesig... |
| CVE-2025-62049 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost ... |
| CVE-2025-62046 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in CodexThemes TheGem Demo Import (for WPBakery) thegem-importer.This issue affects ... |
| CVE-2025-62044 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
| CVE-2025-62038 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Sovlix MeetingHub meetinghub allows Retrieve Embedded... |
| CVE-2025-62037 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62033 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in uxper Togo togo.This issue affects Togo: from n/a through < 1.0.4. |
| CVE-2025-62032 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Clou... |
| CVE-2025-62030 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Comp... |
| CVE-2025-62028 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in ThemeNectar Salient salient.This issue affects Salient: from n/a through < 17.4.0... |
| CVE-2025-62018 | MEDIUM | 5.3 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. |
| CVE-2025-62017 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Missing Authorization vulnerability in hogash KALLYAS kallyas.This issue affects KALLYAS: from n/a through <= 4.22.0. |
| CVE-2025-62012 | MEDIUM | 6.5 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodexThemes TheGem... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now