2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-43335 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | The issue was addressed by adding additional logic. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, ma... |
| CVE-2025-43334 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 1... |
| CVE-2025-43322 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | A logic issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macO... |
| CVE-2025-43288 | MEDIUM | 5.5 | 0.2% | Nov 4, 2025 | This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.7, macOS Tahoe 26... |
| CVE-2025-35021 | MEDIUM | 6.5 | 0.3% | Nov 4, 2025 | By failing to authenticate three times to an unconfigured Abilis CPX device via SSH, an attacker can login to a restrict... |
| CVE-2025-36172 | MEDIUM | 5.4 | 0.1% | Nov 3, 2025 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 001, 24.0.1 through 24.0.1 Interim Fix 004, 24.0... |
| CVE-2025-11193 | MEDIUM | 6.8 | 0.1% | Nov 3, 2025 | A potential vulnerability was reported in some Lenovo Tablets that could allow a local authenticated user or application... |
| CVE-2025-63293 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | FairSketch Rise Ultimate Project Manager & CRM 3.9.4 is vulnerable to Insecure Permissions. A remote authenticated user ... |
| CVE-2025-12657 | MEDIUM | 5.5 | 0.3% | Nov 3, 2025 | The KMIP response parser built into mongo binaries is overly tolerant of certain malformed packets, and may parse them i... |
| CVE-2025-63593 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Grav CMS1.7.49.5 is vulnerable to Cross Site Scripting (XSS). |
| CVE-2025-8558 | MEDIUM | 5.4 | 0.5% | Nov 3, 2025 | Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo... |
| CVE-2025-50363 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Phpgurukul Maid Hiring Management System 1.0 is vulnerable to Cross Site Scripting (XSS) in /maid-hiring.php va the name... |
| CVE-2025-10280 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | IdentityIQ 8.5, IdentityIQ 8.4 and all 8.4 patch levels prior to 8.4p4, IdentityIQ 8.3 and all 8.3 patch levels includin... |
| CVE-2025-63450 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to Cross Site Scripting (XSS) in /carlux/booking.php. |
| CVE-2025-63449 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /orders.php. |
| CVE-2025-63448 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /edit_product.php?id=1. |
| CVE-2025-63447 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_customer.php. |
| CVE-2025-63446 | MEDIUM | 6.1 | 0.2% | Nov 3, 2025 | Water Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /add_vendor.php. |
| CVE-2025-36092 | MEDIUM | 6.5 | 0.4% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause a denial of ... |
| CVE-2025-36091 | MEDIUM | 4.3 | 0.3% | Nov 3, 2025 | IBM Cloud Pak For Business Automation 25.0.0, 24.0.1, and 24.0.0 could allow an authenticated user to cause dashboards t... |
| CVE-2025-63443 | MEDIUM | 5.4 | 0.2% | Nov 3, 2025 | School Management System PHP v1.0 is vulnerable to Cross Site Scripting (XSS) in /login.php via the password parameter. |
| CVE-2025-63442 | MEDIUM | 4.6 | 0.2% | Nov 3, 2025 | Simple User Management System with PHP-MySQL v1.0 is vulnerable to Cross-Site Scripting (XSS) via the Profile Section. T... |
| CVE-2025-60892 | MEDIUM | 6.8 | 0.1% | Nov 3, 2025 | An issue in Raspberry Pi Imager version 1.9.6 for Windows, affecting its OS customization feature. The imager's 'public-... |
| CVE-2025-45663 | MEDIUM | 6.5 | 0.3% | Nov 3, 2025 | An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. |
| CVE-2025-29699 | MEDIUM | 6.5 | 0.3% | Nov 3, 2025 | NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now