2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13302 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file ... |
| CVE-2025-36118 | HIGH | 7.5 | 0.3% | Nov 17, 2025 | IBM Storage Virtualize 8.4, 8.5, 8.7, and 9.1 IKEv1 implementation allows remote attackers to obtain sensitive informati... |
| CVE-2025-13301 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerab... |
| CVE-2025-13300 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unkno... |
| CVE-2025-36357 | HIGH | 8 | 0.7% | Nov 17, 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 could allow a remote authenticated user to traverse directories on the... |
| CVE-2025-36299 | MEDIUM | 4.3 | 0.2% | Nov 17, 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further a... |
| CVE-2025-13299 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown funct... |
| CVE-2025-13298 | CRITICAL | 9.8 | 0.4% | Nov 17, 2025 | A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknow... |
| CVE-2025-63292 | LOW | 3.5 | 0.1% | Nov 17, 2025 | Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x... |
| CVE-2025-13216 | — | — | — | Nov 17, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-64758 | MEDIUM | 4.8 | 0.2% | Nov 17, 2025 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis... |
| CVE-2025-64756 | HIGH | 7.5 | 3.0% | Nov 17, 2025 | Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, th... |
| CVE-2025-64342 | MEDIUM | 6.9 | 0.3% | Nov 17, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it re... |
| CVE-2025-58407 | HIGH | 7.4 | 0.2% | Nov 17, 2025 | Kernel or driver software installed on a Guest VM may post improper commands to the GPU Firmware to exploit a TOCTOU rac... |
| CVE-2025-55059 | MEDIUM | 6.1 | 0.1% | Nov 17, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55058 | CRITICAL | 9.8 | 0.2% | Nov 17, 2025 | CWE-20 Improper Input Validation |
| CVE-2025-55057 | HIGH | 8.8 | 0.1% | Nov 17, 2025 | Multiple CWE-352 Cross-Site Request Forgery (CSRF) |
| CVE-2025-55056 | MEDIUM | 6.1 | 0.1% | Nov 17, 2025 | Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55055 | CRITICAL | 9.8 | 0.7% | Nov 17, 2025 | CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') |
| CVE-2025-34323 | HIGH | 7.8 | 0.3% | Nov 17, 2025 | Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo... |
| CVE-2025-34322 | HIGH | 7.2 | 4.6% | Nov 17, 2025 | Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimen... |
| CVE-2025-13297 | CRITICAL | 9.8 | 0.3% | Nov 17, 2025 | A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impa... |
| CVE-2025-63918 | MEDIUM | 6.2 | 0.3% | Nov 17, 2025 | PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attacker... |
| CVE-2025-63917 | HIGH | 7.1 | 0.3% | Nov 17, 2025 | PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) re... |
| CVE-2025-62519 | HIGH | 7.2 | 0.7% | Nov 17, 2025 | phpMyFAQ is an open source FAQ web application. Prior to version 4.0.14, an authenticated SQL injection vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now