2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65222 | MEDIUM | 4.3 | 2.2% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the rebootTime parameter of /goform/SetSysAutoRebbotCfg. |
| CVE-2025-65221 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow via the list parameter of /goform/setPptpUserList. |
| CVE-2025-65220 | MEDIUM | 4.3 | 0.2% | Nov 20, 2025 | Tenda AC21 V16.03.08.16 is vulnerable to Buffer Overflow in: /goform/SetVirtualServerCfg via the list parameter. |
| CVE-2025-64984 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | Kaspersky has fixed a security issue in Kaspersky Endpoint Security for Linux (any version with anti-virus databases pri... |
| CVE-2025-62346 | MEDIUM | 6.8 | 0.1% | Nov 20, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability was identified in HCL Glovius Cloud. An attacker can force a user's we... |
| CVE-2025-60799 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains an incorrect access control vulnerability in sql.php at lines 68-76. The applicat... |
| CVE-2025-60798 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in display.php at line 396. The application passes ... |
| CVE-2025-60797 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains a SQL injection vulnerability in dataexport.php at line 118. The application dire... |
| CVE-2025-60796 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | phpPgAdmin 7.13.0 and earlier contains multiple cross-site scripting (XSS) vulnerabilities across various components. Us... |
| CVE-2025-60794 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | Session tokens and passwords in couch-auth 0.21.2 are stored in JavaScript objects and remain in memory without explicit... |
| CVE-2025-5092 | MEDIUM | 6.4 | 0.2% | Nov 20, 2025 | Multiple plugins and/or themes for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled ligh... |
| CVE-2025-41076 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | In version 6.13.0 of LimeSurvey, any external user can cause a 500 error in the survey system by sending a malformed ses... |
| CVE-2025-41075 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optin that causes infinite HTTP redirects when accessed directly. Th... |
| CVE-2025-41074 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Vulnerability in LimeSurvey 6.13.0 in the endpoint /optout that causes infinite HTTP redirects when accessed directly. ... |
| CVE-2025-40605 | MEDIUM | 5.3 | 0.3% | Nov 20, 2025 | A Path Traversal vulnerability has been identified in the Email Security appliance allows an attacker to manipulate file... |
| CVE-2025-40604 | CRITICAL | 9.8 | 0.2% | Nov 20, 2025 | Download of Code Without Integrity Check Vulnerability in the SonicWall Email Security appliance loads root filesystem i... |
| CVE-2025-40601 | HIGH | 7.5 | 1.1% | Nov 20, 2025 | A Stack-based buffer overflow vulnerability in the SonicOS SSLVPN service allows a remote unauthenticated attacker to ca... |
| CVE-2025-13469 | MEDIUM | 4.8 | 0.2% | Nov 20, 2025 | A security vulnerability has been detected in Public Knowledge Project omp and ojs 3.3.0/3.4.0/3.5.0. Impacted is an unk... |
| CVE-2025-13468 | HIGH | 8.1 | 0.3% | Nov 20, 2025 | A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_fo... |
| CVE-2025-13451 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | A vulnerability was identified in SourceCodester Online Shop Project 1.0. The affected element is an unknown function of... |
| CVE-2025-13450 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | A vulnerability was determined in SourceCodester Online Shop Project 1.0. Impacted is an unknown function of the file /s... |
| CVE-2025-13449 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | A vulnerability was found in code-projects Online Shop Project 1.0. This issue affects some unknown processing of the fi... |
| CVE-2025-13446 | CRITICAL | 9.8 | 3.4% | Nov 20, 2025 | A vulnerability has been found in Tenda AC21 16.03.08.16. This vulnerability affects unknown code of the file /goform/Se... |
| CVE-2025-13445 | CRITICAL | 9.8 | 3.4% | Nov 20, 2025 | A flaw has been found in Tenda AC21 16.03.08.16. This affects an unknown part of the file /goform/SetIpMacBind. Executin... |
| CVE-2025-13443 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now