2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53896 | HIGH | 8.1 | 0.2% | Nov 29, 2025 | Kiteworks MFT orchestrates end-to-end file transfer workflows. Prior to version 9.1.0, a bug in Kiteworks MFT could caus... |
| CVE-2025-66219 | CRITICAL | 9.8 | 2.4% | Nov 29, 2025 | willitmerge is a command line tool to check if pull requests are mergeable. In versions 0.2.1 and prior, there is a comm... |
| CVE-2025-66201 | HIGH | 8.1 | 0.3% | Nov 29, 2025 | LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-sid... |
| CVE-2025-66036 | MEDIUM | 6.1 | 0.2% | Nov 29, 2025 | Retro is an online platform providing items of vintage collections. Prior to version 2.4.7, Retro is vulnerable to a cro... |
| CVE-2025-66034 | CRITICAL | 9.8 | 0.5% | Nov 29, 2025 | fontTools is a library for manipulating fonts, written in Python. In versions from 4.33.0 to before 4.60.2, the fonttool... |
| CVE-2025-66027 | MEDIUM | 6.5 | 0.3% | Nov 29, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.6, an information disclosure vulnerabil... |
| CVE-2025-65113 | MEDIUM | 6.5 | 0.3% | Nov 29, 2025 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 - #164, an authorization bypass vulnerabi... |
| CVE-2025-65112 | CRITICAL | 9.8 | 0.5% | Nov 29, 2025 | PubNet is a self-hosted Dart & Flutter package service. Prior to version 1.1.3, the /api/storage/upload endpoint in PubN... |
| CVE-2025-64715 | MEDIUM | 5.5 | 0.2% | Nov 29, 2025 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.16.17, 1.... |
| CVE-2025-13683 | MEDIUM | 6.5 | 0.3% | Nov 28, 2025 | Exposure of credentials in unintended requests in Devolutions Server, Remote Desktop Manager on Windows.This issue affec... |
| CVE-2025-12183 | HIGH | 8.8 | 0.6% | Nov 28, 2025 | Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service ... |
| CVE-2025-59792 | MEDIUM | 5.3 | 0.3% | Nov 28, 2025 | Reveals plaintext credentials in the MONITOR command vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks... |
| CVE-2025-59790 | MEDIUM | 5.4 | 0.4% | Nov 28, 2025 | Improper Privilege Management vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from v2.9.0 through v... |
| CVE-2025-51736 | MEDIUM | 6.3 | 0.2% | Nov 28, 2025 | File upload vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-51735 | HIGH | 7.5 | 0.3% | Nov 28, 2025 | CSV formula injection vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-51734 | MEDIUM | 5.4 | 0.2% | Nov 28, 2025 | Cross-site scripting (XSS) vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-51733 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in HCL Technologies Ltd. Unica 12.0.0. |
| CVE-2025-12638 | HIGH | 8 | 0.6% | Nov 28, 2025 | Keras version 3.11.3 is affected by a path traversal vulnerability in the keras.utils.get_file() function when extractin... |
| CVE-2025-11156 | MEDIUM | 5.9 | 0.1% | Nov 28, 2025 | Netskope was notified about a potential gap in its agent (NS Client) on Windows systems. If this gap is successfully ex... |
| CVE-2025-12143 | MEDIUM | 6.9 | 0.2% | Nov 28, 2025 | Stack-based Buffer Overflow vulnerability in ABB Terra AC wallbox.This issue affects Terra AC wallbox: through 1.8.33. |
| CVE-2025-13771 | HIGH | 7.1 | 0.4% | Nov 28, 2025 | WebITR developed by Uniong has an Arbitrary File Read vulnerability, allowing authenticated remote attackers to exploit ... |
| CVE-2025-13770 | HIGH | 7.1 | 0.3% | Nov 28, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar... |
| CVE-2025-13769 | HIGH | 7.1 | 0.3% | Nov 28, 2025 | WebITR developed by Uniong has a SQL Injection vulnerability, allowing authenticated remote attackers to inject arbitrar... |
| CVE-2025-13768 | HIGH | 8.8 | 0.4% | Nov 28, 2025 | WebITR developed by Uniong has an Authentication Bypass vulnerability, allowing authenticated remote attackers to log in... |
| CVE-2025-66386 | MEDIUM | 4.1 | 0.3% | Nov 28, 2025 | app/Model/EventReport.php in MISP before 2.5.27 allows path traversal in view picture for a site-admin. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now