2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66385 | CRITICAL | 9.4 | 0.4% | Nov 28, 2025 | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges ... |
| CVE-2025-66384 | HIGH | 8.2 | 0.3% | Nov 28, 2025 | app/Controller/EventsController.php in MISP before 2.5.24 has invalid logic in checking for uploaded file validity, rela... |
| CVE-2025-66382 | MEDIUM | 5.5 | 0.2% | Nov 28, 2025 | In libexpat through 2.7.3, a crafted file with an approximate size of 2 MiB can lead to dozens of seconds of processing ... |
| CVE-2025-66372 | LOW | 2.8 | 0.1% | Nov 28, 2025 | Mustang before 2.16.3 allows exfiltrating files via XXE attacks. |
| CVE-2025-66371 | MEDIUM | 5 | 0.3% | Nov 28, 2025 | Peppol-py before 1.1.1 allows XXE attacks because of the Saxon configuration. When validating XML-based invoices, the XM... |
| CVE-2025-66370 | MEDIUM | 5 | 0.3% | Nov 28, 2025 | Kivitendo before 3.9.2 allows XXE injection. By uploading an electronic invoice in the ZUGFeRD format, it is possible to... |
| CVE-2025-64312 | HIGH | 7.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma... |
| CVE-2025-58311 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | UAF vulnerability in the USB driver module. Impact: Successful exploitation of this vulnerability will affect availabili... |
| CVE-2025-58308 | LOW | 3.3 | 0.1% | Nov 28, 2025 | Vulnerability of improper criterion security check in the call module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2025-58305 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Identity authentication bypass vulnerability in the Gallery app. Impact: Successful exploitation of this vulnerability m... |
| CVE-2025-58304 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ma... |
| CVE-2025-58302 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2025-13737 | MEDIUM | 4.3 | 0.1% | Nov 28, 2025 | The Nextend Social Login and Register plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2025-64315 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | Configuration defect vulnerability in the file management module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-64314 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the memory management module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-64313 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Denial of service (DoS) vulnerability in the office service. Impact: Successful exploitation of this vulnerability may a... |
| CVE-2025-64311 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the Notepad module. Impact: Successful exploitation of this vulnerability may affect... |
| CVE-2025-58316 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | DoS vulnerability in the video-related system service module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2025-58315 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the Wi-Fi module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2025-58314 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | Vulnerability of accessing invalid memory in the component driver module. Impact: Successful exploitation of this vulner... |
| CVE-2025-58312 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the App Lock module. Impact: Successful exploitation of this vulnerability may affec... |
| CVE-2025-58310 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the distributed component. Impact: Successful exploitation of this vulnerability may... |
| CVE-2025-58309 | HIGH | 7.1 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the startup recovery module. Impact: Successful exploitation of this vulnerability w... |
| CVE-2025-58307 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-58303 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now