2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64513 | CRITICAL | 9.3 | 1.0% | Nov 10, 2025 | Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a... |
| CVE-2025-64512 | HIGH | 7.8 | 0.3% | Nov 10, 2025 | Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documen... |
| CVE-2025-64509 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope... |
| CVE-2025-64508 | HIGH | 7.5 | 0.4% | Nov 10, 2025 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli strea... |
| CVE-2025-64507 | HIGH | 7.8 | 0.1% | Nov 10, 2025 | Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu... |
| CVE-2025-64504 | MEDIUM | 5 | 0.3% | Nov 10, 2025 | Langfuse is an open source large language model engineering platform. Starting in version 2.70.0 and prior to versions 2... |
| CVE-2025-64502 | MEDIUM | 6.9 | 0.4% | Nov 10, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. The MongoDB `exp... |
| CVE-2025-64501 | HIGH | 7.6 | 0.2% | Nov 10, 2025 | ProsemirrorToHtml is a JSON converter which takes ProseMirror-compatible JSON and outputs HTML. In versions 0.2.0 and be... |
| CVE-2025-64484 | HIGH | 8.5 | 0.6% | Nov 10, 2025 | OAuth2-Proxy is an open-source tool that can act as either a standalone reverse proxy or a middleware component integrat... |
| CVE-2025-64183 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64182 | HIGH | 7.8 | 0.2% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64181 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-64167 | MEDIUM | 6.1 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to a cross-sit... |
| CVE-2025-63397 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | Improper input validation in OneFlow v0.9.0 allows attackers to cause a segmentation fault via adding a Python sequence ... |
| CVE-2025-62780 | MEDIUM | 5.4 | 0.4% | Nov 10, 2025 | changedetection.io is a free open source web page change detection tool. A Stored Cross Site Scripting is present in cha... |
| CVE-2025-49145 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, a user that has enough ri... |
| CVE-2025-63617 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | ktg-mes before commit a484f96 (2025-07-03) has a fastjson deserialization vulnerability. This is because it uses a vulne... |
| CVE-2025-63296 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | KERUI K259 5MP Wi-Fi / Tuya Smart Security Camera firmware v33.53.87 contains a code execution vulnerability in its boot... |
| CVE-2025-48878 | MEDIUM | 4.3 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions on the 3.x branch prior to 3.2.2, an insecure direct... |
| CVE-2025-48065 | MEDIUM | 6.1 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ... |
| CVE-2025-48055 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 3.2.2, when displaying content in a browse ... |
| CVE-2025-63384 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | A vulnerability was discovered in RISC-V Rocket-Chip v1.6 and before implementation where the SRET (Supervisor-mode Exce... |
| CVE-2025-63149 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the urls parameter of the get_parentControl_list... |
| CVE-2025-60876 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | BusyBox wget thru 1.3.7 accepted raw CR (0x0D)/LF (0x0A) and other C0 control bytes in the HTTP request-target (path/que... |
| CVE-2025-56503 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | An issue in Sublime HQ Pty Ltd Sublime Text 4 4200 allows authenticated attackers with low-level privileges to escalate ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now