2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66385 | CRITICAL | 9.4 | 0.4% | Nov 28, 2025 | UsersController::edit in Cerebrate before 1.30 allows an authenticated non-privileged user to escalate their privileges ... |
| CVE-2025-12421 | CRITICAL | 9.9 | 0.3% | Nov 27, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that t... |
| CVE-2025-12419 | CRITICAL | 9.9 | 0.3% | Nov 27, 2025 | Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat... |
| CVE-2025-8890 | CRITICAL | 9.3 | 0.9% | Nov 27, 2025 | Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman... |
| CVE-2025-12140 | CRITICAL | 9.3 | 0.4% | Nov 27, 2025 | The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlP... |
| CVE-2025-13675 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ... |
| CVE-2025-13540 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The Tiare Membership plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.... |
| CVE-2025-13539 | CRITICAL | 9.8 | 0.4% | Nov 27, 2025 | The FindAll Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,... |
| CVE-2025-13538 | CRITICAL | 9.8 | 0.3% | Nov 27, 2025 | The FindAll Listing plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0... |
| CVE-2025-62593 | CRITICAL | 9.4 | 0.3% | Nov 26, 2025 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited... |
| CVE-2025-40934 | CRITICAL | 9.3 | 0.1% | Nov 26, 2025 | XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can ... |
| CVE-2025-65276 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/he... |
| CVE-2025-50433 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted p... |
| CVE-2025-65669 | CRITICAL | 9.1 | 0.5% | Nov 26, 2025 | An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without... |
| CVE-2025-26155 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability... |
| CVE-2025-64130 | CRITICAL | 9.8 | 0.9% | Nov 26, 2025 | Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to... |
| CVE-2025-64128 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to e... |
| CVE-2025-64127 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application a... |
| CVE-2025-64126 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter dire... |
| CVE-2025-55469 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac... |
| CVE-2025-65236 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID p... |
| CVE-2025-65235 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via ... |
| CVE-2025-62354 | CRITICAL | 9.8 | 1.2% | Nov 26, 2025 | Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized... |
| CVE-2025-50402 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac... |
| CVE-2025-50399 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now