2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9803 | HIGH | 8.8 | 0.4% | Nov 25, 2025 | lunary-ai/lunary version 1.9.34 is vulnerable to an account takeover due to improper authentication in the Google OAuth ... |
| CVE-2025-65951 | HIGH | 8.7 | 0.1% | Nov 25, 2025 | Inside Track / Entropy Derby is a research-grade horse-racing betting engine. Prior to commit 2d38d2f, the VDF-based tim... |
| CVE-2025-65944 | MEDIUM | 5.1 | 0.3% | Nov 25, 2025 | Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js appl... |
| CVE-2025-64761 | HIGH | 7.2 | 0.3% | Nov 25, 2025 | OpenBao is an open source identity-based secrets management system. Prior to version 2.4.4, a privileged operator could ... |
| CVE-2025-65018 | HIGH | 7.1 | 0.2% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64720 | HIGH | 7.1 | 0.3% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64506 | MEDIUM | 6.1 | 0.1% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64505 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-62155 | HIGH | 8.5 | 0.3% | Nov 25, 2025 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2025-10144 | MEDIUM | 6.5 | 0.2% | Nov 24, 2025 | The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri... |
| CVE-2025-63674 | MEDIUM | 6.8 | 0.3% | Nov 24, 2025 | An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary c... |
| CVE-2025-54563 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-54347 | CRITICAL | 9.9 | 0.6% | Nov 24, 2025 | A Directory Traversal vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6... |
| CVE-2025-54341 | MEDIUM | 5.3 | 0.2% | Nov 24, 2025 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Ha... |
| CVE-2025-54338 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | An Incorrect Access Control vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.1... |
| CVE-2025-63498 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. |
| CVE-2025-52538 | HIGH | 8 | 0.1% | Nov 24, 2025 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p... |
| CVE-2025-48511 | MEDIUM | 5.5 | 0.1% | Nov 24, 2025 | Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti... |
| CVE-2025-48510 | HIGH | 7.1 | 0.1% | Nov 24, 2025 | Improper return value within AMD uProf can allow a local attacker to bypass KSLR, potentially resulting in loss of confi... |
| CVE-2025-36150 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | IBM Concert 1.0.0 through 2.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decry... |
| CVE-2025-29933 | MEDIUM | 5.5 | 0.1% | Nov 24, 2025 | Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a... |
| CVE-2025-0007 | MEDIUM | 5.7 | 0.1% | Nov 24, 2025 | Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user s... |
| CVE-2025-0003 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition poten... |
| CVE-2025-64048 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulner... |
| CVE-2025-64047 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now