2025 CVE Vulnerabilities
45,185 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65278 | HIGH | 7.5 | 0.2% | Nov 26, 2025 | An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers... |
| CVE-2025-65276 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/he... |
| CVE-2025-50433 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted p... |
| CVE-2025-13611 | MEDIUM | 5.3 | 0.2% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha... |
| CVE-2025-12653 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1... |
| CVE-2025-12571 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and ... |
| CVE-2025-66028 | HIGH | 8.2 | 0.3% | Nov 26, 2025 | OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable ... |
| CVE-2025-65966 | HIGH | 8.1 | 0.3% | Nov 26, 2025 | OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea... |
| CVE-2025-65681 | LOW | 3.3 | 0.2% | Nov 26, 2025 | An issue was discovered in Overhang.IO (tutor-open-edx) (overhangio/tutor) 20.0.2 allowing local unauthorized attackers ... |
| CVE-2025-65676 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi... |
| CVE-2025-65675 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi... |
| CVE-2025-65672 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course sett... |
| CVE-2025-65669 | CRITICAL | 9.1 | 0.5% | Nov 26, 2025 | An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without... |
| CVE-2025-26155 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability... |
| CVE-2025-64130 | CRITICAL | 9.8 | 0.9% | Nov 26, 2025 | Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to... |
| CVE-2025-64129 | HIGH | 7.6 | 0.4% | Nov 26, 2025 | Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the... |
| CVE-2025-64128 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to e... |
| CVE-2025-64127 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application a... |
| CVE-2025-64126 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter dire... |
| CVE-2025-55471 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive inf... |
| CVE-2025-55469 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac... |
| CVE-2025-2486 | HIGH | 8.8 | 0.1% | Nov 26, 2025 | The Ubuntu edk2 UEFI firmware packages accidentally allowed the UEFI Shell to be accessed in Secure Boot environments, p... |
| CVE-2025-20373 | LOW | 2.7 | 0.2% | Nov 26, 2025 | In Splunk Add-on for Palo Alto Networks versions below 2.0.2, the add-on exposes client secrets in plain text in the _in... |
| CVE-2025-13084 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ... |
| CVE-2025-11461 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now