2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-55034 | HIGH | 8.8 | 0.2% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow a... |
| CVE-2025-1256 | — | — | — | Nov 14, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-13188 | CRITICAL | 9.8 | 2.2% | Nov 14, 2025 | A vulnerability was detected in D-Link DIR-816L 2_06_b09_beta. Affected by this vulnerability is the function authentica... |
| CVE-2025-13187 | HIGH | 7.5 | 0.5% | Nov 14, 2025 | A security vulnerability has been detected in Intelbras ICIP 2.0.20. Affected is an unknown function of the file /xml/si... |
| CVE-2025-13186 | MEDIUM | 5.4 | 0.2% | Nov 14, 2025 | A weakness has been identified in Bdtask/CodeCanyon Isshue Multi Store eCommerce Shopping Cart Solution up to 4.0. This ... |
| CVE-2025-64084 | MEDIUM | 5.4 | 0.3% | Nov 14, 2025 | An authenticated SQL injection vulnerability exists in Cloudlog 2.7.5 and earlier. The vucc_details_ajax function in app... |
| CVE-2025-63891 | HIGH | 7.5 | 0.4% | Nov 14, 2025 | Information Disclosure in web-accessible backup file in SourceCodester Simple Online Book Store System allows a remote u... |
| CVE-2025-63745 | MEDIUM | 5.5 | 0.1% | Nov 14, 2025 | A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the info() function of bin_n... |
| CVE-2025-63744 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | A NULL pointer dereference vulnerability was discovered in radare2 6.0.5 and earlier within the load() function of bin_d... |
| CVE-2025-13185 | HIGH | 7.2 | 0.3% | Nov 14, 2025 | A security flaw has been discovered in Bdtask/CodeCanyon News365 up to 7.0.3. This affects an unknown function of the fi... |
| CVE-2025-13182 | MEDIUM | 4.8 | 0.2% | Nov 14, 2025 | A vulnerability was identified in pojoin h3blog 1.0. The impacted element is an unknown function of the file /admin/cms/... |
| CVE-2025-63701 | MEDIUM | 6.8 | 0.2% | Nov 14, 2025 | A heap corruption vulnerability exists in the Advantech TP-3250 printer driver's DrvUI_x64_ADVANTECH.dll (v0.3.9200.2078... |
| CVE-2025-13181 | MEDIUM | 4.8 | 0.2% | Nov 14, 2025 | A vulnerability was determined in pojoin h3blog 1.0. The affected element is an unknown function of the file /admin/cms/... |
| CVE-2025-13180 | MEDIUM | 5.4 | 0.2% | Nov 14, 2025 | A vulnerability was found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 2025032... |
| CVE-2025-13179 | MEDIUM | 6.5 | 0.2% | Nov 14, 2025 | A vulnerability has been found in Bdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System up to 20... |
| CVE-2025-13033 | HIGH | 7.5 | 0.5% | Nov 14, 2025 | A vulnerability was identified in the email parsing library due to improper handling of specially formatted recipient em... |
| CVE-2025-63680 | HIGH | 8.6 | 0.3% | Nov 14, 2025 | Nero BackItUp in the Nero Productline is vulnerable to a path parsing/UI rendering flaw (CWE-22) that, in combination wi... |
| CVE-2025-63291 | MEDIUM | 5.4 | 0.2% | Nov 14, 2025 | When processing API requests, the Alteryx server 2022.1.1.42654 and 2024.1 used MongoDB object IDs to uniquely identify ... |
| CVE-2025-13178 | MEDIUM | 5.4 | 0.2% | Nov 14, 2025 | A flaw has been found in Bdtask/CodeCanyon SalesERP up to 20250728. This vulnerability affects unknown code of the file ... |
| CVE-2025-13177 | HIGH | 8.8 | 0.2% | Nov 14, 2025 | A vulnerability was detected in Bdtask/CodeCanyon SalesERP up to 20250728. This affects an unknown part. The manipulatio... |
| CVE-2025-13174 | MEDIUM | 6.3 | 0.2% | Nov 14, 2025 | A weakness has been identified in rachelos WeRSS we-mp-rss up to 1.4.7. Affected by this vulnerability is the function d... |
| CVE-2025-12187 | — | — | — | Nov 14, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-63830 | MEDIUM | 6.1 | 0.2% | Nov 14, 2025 | CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted... |
| CVE-2025-63725 | MEDIUM | 6.1 | 0.2% | Nov 14, 2025 | Reflected Cross-Site Scripting (XSS) vulnerability in SVX Portal 2.7A via the id parameter to Recivers.php. |
| CVE-2025-63724 | MEDIUM | 6 | 0.2% | Nov 14, 2025 | SQL injection (SQL-i) vulnerability in SVX Portal 2.7A via crafted POST request to admin/update_setings.php. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now