2025 CVE Vulnerabilities
45,187 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13084 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | The users endpoint in the groov View API returns a list of all users and associated metadata including their API keys. ... |
| CVE-2025-11461 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Multiple SQL Injections in Frappe CRM Dashboard Controller due to unsafe concatenation of user-controlled parameters int... |
| CVE-2025-65239 | MEDIUM | 4.3 | 0.3% | Nov 26, 2025 | Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.... |
| CVE-2025-65238 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.... |
| CVE-2025-65237 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to e... |
| CVE-2025-65236 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID p... |
| CVE-2025-65235 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via ... |
| CVE-2025-63938 | MEDIUM | 6.5 | 0.2% | Nov 26, 2025 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.... |
| CVE-2025-46175 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Ruoyi v4.8.0 is vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the au... |
| CVE-2025-62354 | CRITICAL | 9.8 | 1.2% | Nov 26, 2025 | Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized... |
| CVE-2025-56396 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | An issue was discovered in Ruoyi 4.8.1 allowing attackers to gain escalated privileges due to the owning department havi... |
| CVE-2025-50402 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac... |
| CVE-2025-50399 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password. |
| CVE-2025-46174 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Ruoyi v4.8.0 vulnerable to Incorrect Access Control. There is a missing checkUserDataScope permission check in the reset... |
| CVE-2025-45311 | HIGH | 8.8 | 0.3% | Nov 26, 2025 | Insecure permissions in fail2ban-client v0.11.2 allows attackers with limited sudo privileges to perform arbitrary opera... |
| CVE-2025-3747 | — | — | — | Nov 26, 2025 | Rejected reason: This CVE ID was duplicated of CVE-2025-32801 |
| CVE-2025-13601 | HIGH | 7.7 | 0.3% | Nov 26, 2025 | A heap-based buffer overflow problem was found in glib through an incorrect calculation of buffer size in the g_escape_u... |
| CVE-2025-9191 | MEDIUM | 6.3 | 0.2% | Nov 26, 2025 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des... |
| CVE-2025-9163 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ... |
| CVE-2025-13674 | MEDIUM | 5.5 | 0.1% | Nov 26, 2025 | BPv7 dissector crash in Wireshark 4.6.0 allows denial of service |
| CVE-2025-62728 | MEDIUM | 5.4 | 0.3% | Nov 26, 2025 | SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thr... |
| CVE-2025-59390 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign... |
| CVE-2025-13735 | HIGH | 7.4 | 0.2% | Nov 26, 2025 | Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is... |
| CVE-2025-9558 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received... |
| CVE-2025-9557 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now