2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63914 | MEDIUM | 6.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.... |
| CVE-2025-56400 | HIGH | 8.8 | 0.1% | Nov 24, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in the OAuth implementation of the Tuya SDK 6.5.0 for Android and iOS, a... |
| CVE-2025-52539 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | A buffer overflow with Xilinx Run Time Environment may allow a local attacker to read or corrupt data from the advanced ... |
| CVE-2025-0005 | HIGH | 7.3 | 0.1% | Nov 24, 2025 | Improper input validation within the XOCL driver may allow a local attacker to generate an integer overflow condition, p... |
| CVE-2025-36112 | MEDIUM | 5.3 | 0.2% | Nov 24, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.... |
| CVE-2025-13466 | MEDIUM | 5.5 | 0.3% | Nov 24, 2025 | body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large n... |
| CVE-2025-13609 | HIGH | 8.2 | 0.4% | Nov 24, 2025 | A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using ... |
| CVE-2025-63958 | CRITICAL | 9.8 | 0.5% | Nov 24, 2025 | MILLENSYS Vision Tools Workspace 6.5.0.2585 exposes a sensitive configuration endpoint (/MILLENSYS/settings) that is acc... |
| CVE-2025-63953 | MEDIUM | 6.5 | 0.1% | Nov 24, 2025 | A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta... |
| CVE-2025-63952 | MEDIUM | 5.7 | 0.1% | Nov 24, 2025 | A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta... |
| CVE-2025-63435 | MEDIUM | 4.3 | 0.3% | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side end... |
| CVE-2025-63434 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | The update mechanism in Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is insecure. The application downl... |
| CVE-2025-63433 | MEDIUM | 4.6 | 0.2% | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt updat... |
| CVE-2025-63432 | MEDIUM | 4.6 | 0.1% | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior is Missing SSL Certificate Validation. The application fai... |
| CVE-2025-13594 | — | — | — | Nov 24, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-13511 | — | — | — | Nov 24, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-60917 | MEDIUM | 4.6 | 0.2% | Nov 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti... |
| CVE-2025-60916 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A reflected cross-site scripting (XSS) vulnerability in the /overview/network/ endpoint of Austrian Archaeological Insti... |
| CVE-2025-60915 | HIGH | 8.1 | 0.4% | Nov 24, 2025 | An issue in the size query parameter (/views/file.py) of Austrian Archaeological Institute Openatlas before v8.12.0 allo... |
| CVE-2025-60914 | MEDIUM | 4.6 | 0.2% | Nov 24, 2025 | Incorrect access control in Austrian Archaeological Institute Openatlas before v8.12.0 allows attackers to access sensit... |
| CVE-2025-60638 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ... |
| CVE-2025-60633 | MEDIUM | 6.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via the Nudm_Subs... |
| CVE-2025-60632 | MEDIUM | 6.5 | 0.2% | Nov 24, 2025 | An issue was discovered in Free5GC v4.0.0 and v4.0.1 allowing an attacker to cause a denial of service via crafted POST ... |
| CVE-2025-56423 | MEDIUM | 5.3 | 0.3% | Nov 24, 2025 | An issue in Austrian Academy of Sciences (AW) Austrian Archaeological Institute OpenAtlas v.8.12.0 allows a remote attac... |
| CVE-2025-56401 | HIGH | 7.6 | 0.2% | Nov 24, 2025 | ZIRA Group WBRM 7.0 is vulnerable to SQL Injection in referenceLookupsByTableNameAndColumnName. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now