2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13410 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A vulnerability has been found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected is an unknown function of ... |
| CVE-2025-13147 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before ... |
| CVE-2025-65103 | HIGH | 8.8 | 0.3% | Nov 19, 2025 | OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to version 2.9.5, an ... |
| CVE-2025-63932 | HIGH | 7.3 | 6.4% | Nov 19, 2025 | D-Link Router DIR-868L A1 FW106KRb01.bin has an unauthenticated remote code execution vulnerability in the cgibin binary... |
| CVE-2025-63214 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauth... |
| CVE-2025-63213 | CRITICAL | 9.8 | 0.8% | Nov 19, 2025 | The QVidium Opera11 device (firmware version 2.9.0-Ax4x-opera11) is vulnerable to Remote Code Execution (RCE) due to imp... |
| CVE-2025-63212 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti... |
| CVE-2025-51663 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | A vulnerability found in IPRateLimit implementation of FileCodeBox up to 2.2 allows remote attackers to bypass ip-based ... |
| CVE-2025-51662 | MEDIUM | 5.4 | 0.1% | Nov 19, 2025 | A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and ea... |
| CVE-2025-51661 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | A path Traversal vulnerability found in FileCodeBox v2.2 and earlier allows arbitrary file writes when application is co... |
| CVE-2025-36371 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache impl... |
| CVE-2025-65100 | MEDIUM | 6.9 | 0.3% | Nov 19, 2025 | Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT... |
| CVE-2025-65094 | HIGH | 8.8 | 0.3% | Nov 19, 2025 | WBCE CMS is a content management system. Prior to version 1.6.4, a low-privileged user in WBCE CMS can escalate their pr... |
| CVE-2025-64759 | MEDIUM | 6.1 | 0.3% | Nov 19, 2025 | Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of ... |
| CVE-2025-63211 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5... |
| CVE-2025-65099 | CRITICAL | 9.8 | 0.4% | Nov 19, 2025 | Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude... |
| CVE-2025-65095 | CRITICAL | 9.4 | 0.3% | Nov 19, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-65089 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to ver... |
| CVE-2025-65034 | HIGH | 8.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization vulnerabil... |
| CVE-2025-65033 | HIGH | 8.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the poll ma... |
| CVE-2025-65032 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-65031 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th... |
| CVE-2025-65030 | HIGH | 7.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an authorization flaw in the comment... |
| CVE-2025-65029 | HIGH | 8.1 | 0.3% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ... |
| CVE-2025-65028 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now