2025 CVE Vulnerabilities
45,199 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66019 | MEDIUM | 6.6 | 0.3% | Nov 26, 2025 | pypdf is a free and open-source pure-python PDF library. Prior to version 6.4.0, an attacker who uses this vulnerability... |
| CVE-2025-65963 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient... |
| CVE-2025-65957 | HIGH | 8.8 | 0.2% | Nov 26, 2025 | Core Bot Is an Open Source discord bot made for maple hospital servers. Prior to commit dffe050, the API keys (SUPABASE_... |
| CVE-2025-65956 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Formwork is a flat file-based Content Management System (CMS). Prior to version 2.2.0, inserting unsanitized data into t... |
| CVE-2025-65953 | MEDIUM | 6 | 0.2% | Nov 25, 2025 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to version 0.22.5, a Heap-Use-After-Free (UA... |
| CVE-2025-65952 | HIGH | 8.7 | 0.4% | Nov 25, 2025 | Console is a network used to control Gorilla Tag mods' users and other users on the network. Prior to version 2.8.0, a p... |
| CVE-2025-65942 | LOW | 2.7 | 0.3% | Nov 25, 2025 | VictoriaMetrics is a scalable solution for monitoring and managing time series data. In versions from 1.0.0 to before 1.... |
| CVE-2025-64713 | HIGH | 7.4 | 0.3% | Nov 25, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, an out-... |
| CVE-2025-64704 | MEDIUM | 5.5 | 0.2% | Nov 25, 2025 | WebAssembly Micro Runtime (WAMR) is a lightweight standalone WebAssembly (Wasm) runtime. Prior to version 2.4.4, WAMR is... |
| CVE-2025-13597 | CRITICAL | 9.8 | 0.9% | Nov 25, 2025 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual... |
| CVE-2025-13595 | CRITICAL | 9.8 | 0.9% | Nov 25, 2025 | The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu... |
| CVE-2025-63735 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | A reflected Cross site scripting (XSS) vulnerability in Ruckus Unleashed 200.13.6.1.319 via the name parameter to the th... |
| CVE-2025-62703 | HIGH | 8.8 | 0.7% | Nov 25, 2025 | Fugue is a unified interface for distributed computing that lets users execute Python, Pandas, and SQL code on Spark, Da... |
| CVE-2025-21621 | MEDIUM | 6.1 | 0.3% | Nov 25, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. Prior to version 2.25.0, a refle... |
| CVE-2025-58360 | CRITICAL | 9.8 | 66.8% | Nov 25, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.... |
| CVE-2025-51746 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjso... |
| CVE-2025-51745 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization... |
| CVE-2025-51744 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserializatio... |
| CVE-2025-51743 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to... |
| CVE-2025-51741 | HIGH | 7.5 | 0.4% | Nov 25, 2025 | An issue was discovered in Veal98 Echo Open-Source Community System 2.2 thru 2.3 allowing an unauthenticated attacker to... |
| CVE-2025-9624 | HIGH | 7.5 | 0.5% | Nov 25, 2025 | A vulnerability in OpenSearch allows attackers to cause Denial of Service (DoS) by submitting complex query_string input... |
| CVE-2025-66017 | HIGH | 8.2 | 0.2% | Nov 25, 2025 | CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab... |
| CVE-2025-66016 | CRITICAL | 9.3 | 0.2% | Nov 25, 2025 | CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab... |
| CVE-2025-65965 | HIGH | 8.2 | 0.1% | Nov 25, 2025 | Grype is a vulnerability scanner for container images and filesystems. A credential disclosure vulnerability was found i... |
| CVE-2025-65647 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | Insecure Direct Object Reference (IDOR) in the Track order function in PHPGURUKUL Online Shopping Portal 2.1 allows info... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now