2025 CVE Vulnerabilities
45,191 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59390 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign... |
| CVE-2025-13735 | HIGH | 7.4 | 0.2% | Nov 26, 2025 | Out-of-bounds Read vulnerability in ASR1903、ASR3901 in ASR Lapwing_Linux on Linux (nr_fw modules). This vulnerability is... |
| CVE-2025-9558 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | There is a potential OOB Write vulnerability in the gen_prov_start function in pb_adv.c. The full length of the received... |
| CVE-2025-9557 | HIGH | 7.6 | 0.2% | Nov 26, 2025 | An out-of-bound write can lead to an arbitrary code execution. Even on devices with some form of memory protection, thi... |
| CVE-2025-59820 | MEDIUM | 6.7 | 0.2% | Nov 26, 2025 | In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex... |
| CVE-2025-55174 | LOW | 3.2 | 0.1% | Nov 26, 2025 | In KDE Skanpage before 25.08.0, an attempt at file overwrite can result in the contents of the new file at the beginning... |
| CVE-2025-12061 | HIGH | 8.6 | 0.2% | Nov 26, 2025 | The TAX SERVICE Electronic HDM WordPress plugin before 1.2.1 does not authorization and CSRF checks in an AJAX action, a... |
| CVE-2025-64983 | HIGH | 8.6 | 0.3% | Nov 26, 2025 | Smart Video Doorbell firmware versions prior to 2.01.078 contain an active debug code vulnerability that allows an attac... |
| CVE-2025-66235 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66234 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66233 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66232 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66231 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66230 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66229 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66228 | — | — | — | Nov 26, 2025 | Rejected reason: Not used |
| CVE-2025-66026 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the M... |
| CVE-2025-66025 | MEDIUM | 4.3 | 0.2% | Nov 26, 2025 | Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page i... |
| CVE-2025-66022 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa... |
| CVE-2025-66269 | HIGH | 7.1 | 0.1% | Nov 26, 2025 | The RupsMon and USBMate services in UPSilon 2000 run with SYSTEM privileges and contain unquoted service paths. This all... |
| CVE-2025-66266 | CRITICAL | 9.3 | 0.1% | Nov 26, 2025 | The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control.... |
| CVE-2025-66021 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by thir... |
| CVE-2025-66020 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action i... |
| CVE-2025-12848 | MEDIUM | 6.1 | 0.3% | Nov 26, 2025 | Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ... |
| CVE-2025-66265 | MEDIUM | 6.9 | 0.1% | Nov 26, 2025 | CMService.exe creates the C:\\usr directory and subdirectories with insecure permissions, granting write access to all a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now