2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63716 | MEDIUM | 6.5 | 0.1% | Nov 7, 2025 | The SourceCodester Leads Manager Tool v1.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks that allow unautho... |
| CVE-2025-63714 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Cross-Site Scripting (XSS) vulnerability in SourceCodester User Account Generator 1.0 allows remote attackers to execute... |
| CVE-2025-63713 | MEDIUM | 6.1 | 0.3% | Nov 7, 2025 | Cross-Site Scripting (XSS) vulnerability in SourceCodester "MatchMaster" 1.0 allows remote attackers to inject arbitrary... |
| CVE-2025-57697 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | AstrBot Project v3.5.22 has an arbitrary file read vulnerability in function _encode_image_bs64. Since the _encode_image... |
| CVE-2025-12829 | MEDIUM | 6.9 | 0.1% | Nov 7, 2025 | An uninitialized stack read issue exists in Amazon Ion-C versions <v1.1.4 that may allow a threat actor to craft data an... |
| CVE-2025-7719 | MEDIUM | 5.3 | 0.3% | Nov 7, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in GE Vernova Smallworld on... |
| CVE-2025-63785 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the text editor feature of the Onlook web application 0.2... |
| CVE-2025-63784 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An Open Redirect vulnerability exists in the OAuth callback handler in file onlook/apps/web/client/src/app/auth/callback... |
| CVE-2025-63687 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/... |
| CVE-2025-63686 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116... |
| CVE-2025-58465 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us... |
| CVE-2025-58463 | MEDIUM | 4.9 | 0.4% | Nov 7, 2025 | A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi... |
| CVE-2025-57712 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-57706 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user... |
| CVE-2025-54168 | MEDIUM | 4.8 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin... |
| CVE-2025-53413 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53412 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-53411 | MEDIUM | 4.9 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53410 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53409 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53408 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-52865 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-47207 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain... |
| CVE-2025-46413 | MEDIUM | 5.3 | 0.1% | Nov 7, 2025 | Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W... |
| CVE-2025-10966 | MEDIUM | 4.3 | 0.4% | Nov 7, 2025 | curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now