2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11936 | MEDIUM | 5.3 | 0.4% | Nov 21, 2025 | Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u... |
| CVE-2025-11934 | LOW | 2.7 | 0.1% | Nov 21, 2025 | Improper input validation in the TLS 1.3 CertificateVerify signature algorithm negotiation in wolfSSL 5.8.2 and earlier ... |
| CVE-2025-11933 | MEDIUM | 6.5 | 0.4% | Nov 21, 2025 | Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows... |
| CVE-2025-11932 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info... |
| CVE-2025-11931 | HIGH | 8.2 | 0.3% | Nov 21, 2025 | Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a cal... |
| CVE-2025-65111 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to ... |
| CVE-2025-65109 | HIGH | 8.5 | 0.2% | Nov 21, 2025 | Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and... |
| CVE-2025-65108 | CRITICAL | 10 | 0.9% | Nov 21, 2025 | md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, ... |
| CVE-2025-65107 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from... |
| CVE-2025-65106 | HIGH | 8.3 | 0.5% | Nov 21, 2025 | LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1... |
| CVE-2025-65102 | HIGH | 8.7 | 0.3% | Nov 21, 2025 | PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the inpu... |
| CVE-2025-65092 | MEDIUM | 6.9 | 0.3% | Nov 21, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the E... |
| CVE-2025-43374 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad... |
| CVE-2025-31266 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f... |
| CVE-2025-31248 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2025-31216 | LOW | 2.4 | 0.1% | Nov 21, 2025 | The issue was addressed with improved checks. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7. An attacke... |
| CVE-2025-11935 | HIGH | 7.5 | 0.2% | Nov 21, 2025 | With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy... |
| CVE-2025-0504 | MEDIUM | 5.4 | 0.1% | Nov 21, 2025 | Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with th... |
| CVE-2025-11087 | HIGH | 8.8 | 0.2% | Nov 21, 2025 | The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up ... |
| CVE-2025-36149 | MEDIUM | 5.4 | 0.2% | Nov 21, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim. |
| CVE-2025-13524 | MEDIUM | 6.8 | 0.2% | Nov 21, 2025 | Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linu... |
| CVE-2025-64767 | CRITICAL | 9.1 | 0.2% | Nov 21, 2025 | hpke-js is a Hybrid Public Key Encryption (HPKE) module built on top of Web Cryptography API. Prior to version 1.7.5, th... |
| CVE-2025-64169 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to befo... |
| CVE-2025-62626 | HIGH | 7.2 | 0.2% | Nov 21, 2025 | Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned ... |
| CVE-2025-62609 | HIGH | 7.5 | 0.3% | Nov 21, 2025 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now