2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20378 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9... |
| CVE-2025-63419 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share... |
| CVE-2025-59491 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields. |
| CVE-2025-59089 | MEDIUM | 5.9 | 0.5% | Nov 12, 2025 | If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery... |
| CVE-2025-59088 | HIGH | 8.6 | 0.4% | Nov 12, 2025 | If kdcproxy receives a request for a realm which does not have server addresses defined in its configuration, by default... |
| CVE-2025-52331 | MEDIUM | 6.1 | 0.3% | Nov 12, 2025 | Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to... |
| CVE-2025-2843 | HIGH | 8.8 | 0.3% | Nov 12, 2025 | A flaw was found in the Observability Operator. The Operator creates a ServiceAccount with *ClusterRole* upon deployment... |
| CVE-2025-13042 | HIGH | 8.8 | 0.2% | Nov 12, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exp... |
| CVE-2025-11797 | HIGH | 7.8 | 0.1% | Nov 12, 2025 | A maliciously crafted DWG file, when parsed through Autodesk 3ds Max, can force a Use-After-Free vulnerability. A malici... |
| CVE-2025-11795 | HIGH | 7.8 | 0.1% | Nov 12, 2025 | A maliciously crafted JPG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ... |
| CVE-2025-9316 | MEDIUM | 6.9 | 36.7% | Nov 12, 2025 | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. |
| CVE-2025-64293 | HIGH | 7.6 | 0.2% | Nov 12, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Golemiq 0 Day Anal... |
| CVE-2025-64281 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel ... |
| CVE-2025-64280 | CRITICAL | 9.8 | 0.3% | Nov 12, 2025 | A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permi... |
| CVE-2025-63353 | CRITICAL | 9.8 | 1.2% | Nov 12, 2025 | A vulnerability in FiberHome GPON ONU HG6145F1 RP4423 allows the device's factory default Wi-Fi password (WPA/WPA2 pre-s... |
| CVE-2025-63289 | CRITICAL | 9.1 | 0.2% | Nov 12, 2025 | Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryptio... |
| CVE-2025-12152 | — | — | — | Nov 12, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-12068 | — | — | — | Nov 12, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2025-11700 | HIGH | 7.5 | 31.0% | Nov 12, 2025 | N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure |
| CVE-2025-11367 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization |
| CVE-2025-11366 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | N-central < 2025.4 is vulnerable to authentication bypass via path traversal |
| CVE-2025-63667 | HIGH | 7.5 | 0.4% | Nov 12, 2025 | Incorrect access control in SIMICAM v1.16.41-20250725, KEVIEW v1.14.92-20241120, ASECAM v1.14.10-20240725 allows attacke... |
| CVE-2025-63666 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and ... |
| CVE-2025-11567 | HIGH | 7.3 | 0.1% | Nov 12, 2025 | CWE-276: Incorrect Default Permissions vulnerability exists that could cause elevated system access when the target inst... |
| CVE-2025-11566 | MEDIUM | 6.9 | 0.5% | Nov 12, 2025 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now