2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-44018 | HIGH | 8.3 | 0.2% | Nov 24, 2025 | A firmware downgrade vulnerability exists in the OTA Update functionality of GL-Inet GL-AXT1800 4.7.0. A specially craft... |
| CVE-2025-40213 | HIGH | 7.8 | 0.2% | Nov 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: fix crash in set_mesh_sync and set... |
| CVE-2025-10555 | HIGH | 8.7 | 0.2% | Nov 24, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in DELMIA Service Process Engineer ... |
| CVE-2025-10554 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A stored Cross-site Scripting (XSS) vulnerability affecting Requirements in ENOVIA Product Manager from Release 3DEXPERI... |
| CVE-2025-13598 | — | — | — | Nov 24, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-13541 | — | — | — | Nov 24, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-12978 | MEDIUM | 5.4 | 0.3% | Nov 24, 2025 | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins contain a flaw in the tag_key validation logic that fa... |
| CVE-2025-12977 | CRITICAL | 9.1 | 0.6% | Nov 24, 2025 | Fluent Bit in_http, in_splunk, and in_elasticsearch input plugins fail to sanitize tag_key inputs. An attacker with netw... |
| CVE-2025-12972 | MEDIUM | 5.3 | 0.7% | Nov 24, 2025 | Fluent Bit out_file plugin does not properly sanitize tag values when deriving output file names. When the File option i... |
| CVE-2025-12970 | HIGH | 8.8 | 0.8% | Nov 24, 2025 | The extract_name function in Fluent Bit in_docker input plugin copies container names into a fixed size stack buffer wit... |
| CVE-2025-12969 | MEDIUM | 6.5 | 0.6% | Nov 24, 2025 | Fluent Bit in_forward input plugin does not properly enforce the security.users authentication mechanism under certain c... |
| CVE-2025-11921 | HIGH | 8.5 | 0.6% | Nov 24, 2025 | iStats contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root via c... |
| CVE-2025-65998 | HIGH | 7.5 | 0.4% | Nov 24, 2025 | Apache Syncope can be configured to store the user password values in the internal database with AES encryption, though ... |
| CVE-2025-65503 | MEDIUM | 5.5 | 0.2% | Nov 24, 2025 | Use after free in endpoint destructors in Redboltz async_mqtt 10.2.5 allows local users to cause a denial of service via... |
| CVE-2025-65502 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | Null pointer dereference in add_ca_certs() in Cesanta Mongoose before 7.2 allows remote attackers to cause a denial of s... |
| CVE-2025-65501 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | Null pointer dereference in coap_dtls_info_callback() in OISM libcoap 4.3.5 allows remote attackers to cause a denial of... |
| CVE-2025-65500 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65499 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | Array index error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause... |
| CVE-2025-65498 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65497 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65496 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-65495 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | Integer signedness error in tls_verify_call_back() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers t... |
| CVE-2025-65494 | HIGH | 7.5 | 0.2% | Nov 24, 2025 | NULL pointer dereference in get_san_or_cn_from_cert() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attacker... |
| CVE-2025-65493 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | NULL pointer dereference in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attackers to cause a denial of servic... |
| CVE-2025-41017 | MEDIUM | 6.9 | 0.2% | Nov 24, 2025 | Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now