2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63685 | CRITICAL | 9.8 | 0.3% | Nov 20, 2025 | Quark Cloud Drive v3.23.2 has a DLL Hijacking vulnerability. This vulnerability stems from the insecure loading of syste... |
| CVE-2025-62674 | HIGH | 7 | 0.2% | Nov 20, 2025 | The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an a... |
| CVE-2025-25613 | HIGH | 7.5 | 0.2% | Nov 20, 2025 | FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2... |
| CVE-2025-55124 | MEDIUM | 6.1 | 0.4% | Nov 20, 2025 | Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script. |
| CVE-2025-55123 | MEDIUM | 5.4 | 0.4% | Nov 20, 2025 | Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be a... |
| CVE-2025-52671 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes ... |
| CVE-2025-52670 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete... |
| CVE-2025-52669 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes no... |
| CVE-2025-52668 | MEDIUM | 5.4 | 0.4% | Nov 20, 2025 | Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier version... |
| CVE-2025-52667 | MEDIUM | 5.4 | 0.3% | Nov 20, 2025 | Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS... |
| CVE-2025-52666 | LOW | 2.7 | 0.4% | Nov 20, 2025 | Improper neutralisation of format characters in the settings of Revive Adserver 5.5.2 and 6.0.1 and earlier versions cau... |
| CVE-2025-48987 | MEDIUM | 6.1 | 0.4% | Nov 20, 2025 | Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XS... |
| CVE-2025-48986 | HIGH | 8.8 | 0.6% | Nov 20, 2025 | Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe... |
| CVE-2025-35029 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authent... |
| CVE-2025-63700 | — | — | — | Nov 20, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
| CVE-2025-55128 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in th... |
| CVE-2025-55127 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the userna... |
| CVE-2025-55126 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box ... |
| CVE-2025-10571 | CRITICAL | 9.6 | 0.3% | Nov 20, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in ABB ABB Ability Edgenius.This issue affects AB... |
| CVE-2025-64524 | MEDIUM | 5.5 | 0.2% | Nov 20, 2025 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operati... |
| CVE-2025-63889 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary fil... |
| CVE-2025-63888 | CRITICAL | 9.8 | 0.5% | Nov 20, 2025 | The read function in file thinkphp\library\think\template\driver\File.php in ThinkPHP 5.0.24 contains a remote code exec... |
| CVE-2025-64428 | CRITICAL | 9.8 | 0.5% | Nov 20, 2025 | Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection.... |
| CVE-2025-64185 | MEDIUM | 6.9 | 0.2% | Nov 20, 2025 | Open OnDemand is an open-source HPC portal. Prior to versions 4.0.8 and 3.1.16, Open OnDemand packages create world writ... |
| CVE-2025-64027 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Snipe-IT v8.3.4 (build 20218) contains a reflected cross-site scripting (XSS) vulnerability in the CSV Import workflow. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now