2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13782 | CRITICAL | 9.8 | 0.3% | Nov 30, 2025 | A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is... |
| CVE-2025-66424 | MEDIUM | 6.5 | 0.2% | Nov 30, 2025 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for data export. This is fixed in 7.6.11, 7.4.21, 7.0.40... |
| CVE-2025-66423 | HIGH | 7.1 | 0.2% | Nov 30, 2025 | Tryton trytond 6.0 before 7.6.11 does not enforce access rights for the route of the HTML editor. This is fixed in 7.6.1... |
| CVE-2025-66422 | MEDIUM | 4.3 | 0.2% | Nov 30, 2025 | Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is ... |
| CVE-2025-66421 | MEDIUM | 5.4 | 0.1% | Nov 30, 2025 | Tryton sao (aka tryton-sao) before 7.6.11 allows XSS because it does not escape completion values. This is fixed in 7.6.... |
| CVE-2025-66420 | MEDIUM | 5.4 | 0.1% | Nov 30, 2025 | Tryton sao (aka tryton-sao) before 7.6.9 allows XSS via an HTML attachment. This is fixed in 7.6.9, 7.4.19, 7.0.38, and ... |
| CVE-2025-13615 | CRITICAL | 9.8 | 0.3% | Nov 30, 2025 | The StreamTube Core plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and includin... |
| CVE-2025-6666 | LOW | 2 | 0.1% | Nov 29, 2025 | A vulnerability was determined in motogadget mo.lock Ignition Lock up to 20251125. Affected by this vulnerability is an ... |
| CVE-2025-66291 | MEDIUM | 4.3 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the interview attachment r... |
| CVE-2025-66290 | MEDIUM | 4.3 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application’s recruitm... |
| CVE-2025-66289 | HIGH | 8.8 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application does not i... |
| CVE-2025-66225 | HIGH | 8.8 | 0.2% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the password reset workflo... |
| CVE-2025-66224 | HIGH | 8.8 | 0.5% | Nov 29, 2025 | OrangeHRM is a comprehensive human resource management (HRM) system. From version 5.0 to 5.7, the application contains a... |
| CVE-2025-65892 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Reflected Cross-Site Scripting (rXSS) in krpano before version 1.23.2 allows a remote unauthenticated attacker to execut... |
| CVE-2025-65540 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Multiple Cross-Site Scripting (XSS) vulnerabilities exist in xmall v1.1 due to improper handling of user-supplied data. ... |
| CVE-2025-66223 | HIGH | 8.4 | 0.2% | Nov 29, 2025 | OpenObserve is a cloud-native observability platform. Prior to version 0.16.0, organization invitation tokens do not exp... |
| CVE-2025-66221 | MEDIUM | 5.3 | 0.5% | Nov 29, 2025 | Werkzeug is a comprehensive WSGI web application library. Prior to version 3.1.4, Werkzeug's safe_join function allows p... |
| CVE-2025-66217 | HIGH | 7.5 | 0.6% | Nov 29, 2025 | AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, an integer underflow vulnerability exists in the MQ... |
| CVE-2025-66216 | CRITICAL | 9.8 | 0.4% | Nov 29, 2025 | AIS-catcher is a multi-platform AIS receiver. Prior to version 0.64, a heap buffer overflow vulnerability has been ident... |
| CVE-2025-61915 | MEDIUM | 6.7 | 0.4% | Nov 29, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.... |
| CVE-2025-58436 | MEDIUM | 5.5 | 0.2% | Nov 29, 2025 | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.... |
| CVE-2025-53939 | HIGH | 8.8 | 0.6% | Nov 29, 2025 | Kiteworks is a private data network (PDN). Prior to version 9.1.0, improper input validation when managing roles of a sh... |
| CVE-2025-53900 | HIGH | 8.8 | 1.0% | Nov 29, 2025 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, an unfavourable definition of rol... |
| CVE-2025-53899 | HIGH | 7.2 | 0.8% | Nov 29, 2025 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, the back-end of Kiteworks MFT is ... |
| CVE-2025-53897 | MEDIUM | 6.8 | 0.2% | Nov 29, 2025 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, this vulnerability could allow an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now