2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60691 | HIGH | 8.8 | 0.7% | Nov 13, 2025 | A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.... |
| CVE-2025-60690 | HIGH | 8.8 | 4.4% | Nov 13, 2025 | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F... |
| CVE-2025-20355 | MEDIUM | 4.7 | 0.2% | Nov 13, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst Center Virtual Appliance could allow an unauthen... |
| CVE-2025-20353 | MEDIUM | 6.1 | 0.2% | Nov 13, 2025 | A vulnerability in the web-based management interface of Cisco Catalyst Center could allow an unauthenticated, remote at... |
| CVE-2025-20349 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitr... |
| CVE-2025-20346 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | A vulnerability in Cisco Catalyst Center could allow an authenticated, remote attacker to execute operations that should... |
| CVE-2025-20341 | HIGH | 8.8 | 0.5% | Nov 13, 2025 | A vulnerability in Cisco Catalyst Center Virtual Appliance could allow an authenticated, remote attacker to elevate priv... |
| CVE-2025-13121 | HIGH | 7.3 | 0.3% | Nov 13, 2025 | A security vulnerability has been detected in cameasy Liketea 1.0.0. Impacted is the function list of the file laravel/a... |
| CVE-2025-11538 | MEDIUM | 6.8 | 0.5% | Nov 13, 2025 | A vulnerability exists in Keycloak's server distribution where enabling debug mode (--debug <port>) insecurely defaults ... |
| CVE-2025-64718 | MEDIUM | 5.3 | 0.4% | Nov 13, 2025 | js-yaml is a JavaScript YAML parser and dumper. In js-yaml before 4.1.1 and 3.14.2, it's possible for an attacker to mod... |
| CVE-2025-64717 | CRITICAL | 9.8 | 0.4% | Nov 13, 2025 | ZITADEL is an open source identity management platform. Starting in version 2.50.0 and prior to versions 2.71.19, 3.4.4,... |
| CVE-2025-64714 | MEDIUM | 5.8 | 0.4% | Nov 13, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior... |
| CVE-2025-64703 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations b... |
| CVE-2025-64525 | MEDIUM | 6.5 | 1.1% | Nov 13, 2025 | Astro is a web framework. In Astro versions 2.16.0 up to but excluding 5.15.5 which utilizeon-demand rendering, request ... |
| CVE-2025-64511 | HIGH | 8.8 | 0.2% | Nov 13, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network serv... |
| CVE-2025-62484 | CRITICAL | 9.8 | 0.3% | Nov 13, 2025 | Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthent... |
| CVE-2025-60689 | MEDIUM | 5.4 | 8.5% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200... |
| CVE-2025-60688 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681... |
| CVE-2025-60687 | MEDIUM | 6.5 | 6.3% | Nov 13, 2025 | An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B2023013... |
| CVE-2025-60686 | MEDIUM | 5.1 | 0.2% | Nov 13, 2025 | A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink router... |
| CVE-2025-60685 | MEDIUM | 5.1 | 0.2% | Nov 13, 2025 | A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (s... |
| CVE-2025-60684 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681... |
| CVE-2025-60683 | MEDIUM | 6.5 | 1.1% | Nov 13, 2025 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf... |
| CVE-2025-60682 | MEDIUM | 6.5 | 1.6% | Nov 13, 2025 | A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudup... |
| CVE-2025-52186 | MEDIUM | 6.5 | 0.3% | Nov 13, 2025 | Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now