2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12428 | HIGH | 8.8 | 6.8% | Nov 10, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write v... |
| CVE-2025-63288 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | In Open5GS 2.7.6, AMF crashes when receiving an abnormal NGSetupRequest message, resulting in denial of service. |
| CVE-2025-47773 | MEDIUM | 6.1 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ... |
| CVE-2025-47286 | HIGH | 7.2 | 0.4% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. In versions prior to 2.7.13 and 3.2.2, an administrator can, by ... |
| CVE-2025-43723 | HIGH | 7.5 | 0.2% | Nov 10, 2025 | Dell PowerScale OneFS, versions prior to 9.10.1.3 and versions 9.11.0.0 through 9.12.0.0, contains a use of a broken or ... |
| CVE-2025-43079 | MEDIUM | 6.3 | 0.1% | Nov 10, 2025 | The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported ve... |
| CVE-2025-12967 | HIGH | 8.6 | 0.4% | Nov 10, 2025 | An issue in AWS Wrappers for Amazon Aurora PostgreSQL may allow for privilege escalation to rds_superuser role. A low pr... |
| CVE-2025-63835 | HIGH | 8.8 | 0.6% | Nov 10, 2025 | A stack-based buffer overflow vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exists in... |
| CVE-2025-63834 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exi... |
| CVE-2025-63497 | HIGH | 7.1 | 0.2% | Nov 10, 2025 | The patient prescription viewing functionality in his_doc_view_single_patient.php of rickxy Hospital Management System v... |
| CVE-2025-63457 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the wanMTU parameter in the sub_4F55C function. Th... |
| CVE-2025-63456 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the time parameter in the SetSysTimeCfg function. ... |
| CVE-2025-63455 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the shareSpeed parameter in the fromSetWifiGus... |
| CVE-2025-63147 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the deviceId parameter of the saveParentControlI... |
| CVE-2025-63154 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the addEffect parameter of the urld... |
| CVE-2025-63153 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | TOTOLink A7000R V9.1.0u.6115_B20201022 was discovered to contain a stack overflow in the ssid parameter of the urldecode... |
| CVE-2025-63152 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Tenda AX3 V16.03.12.10_CN was discovered to contain a stack overflow in the wpapsk_crypto parameter of the wlSetExternPa... |
| CVE-2025-46430 | HIGH | 7.3 | 0.1% | Nov 10, 2025 | Dell Display and Peripheral Manager, versions prior to 2.1.2.12, contains an Execution with Unnecessary Privileges vulne... |
| CVE-2025-8768 | — | — | — | Nov 10, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-12020. Reason: This candidate is a ... |
| CVE-2025-63712 | HIGH | 8.8 | 0.2% | Nov 10, 2025 | Cross-Site Request Forgery (CSRF) in SourceCodester Product Expiry Management System. The User Management module (delete... |
| CVE-2025-63711 | HIGH | 7.1 | 0.2% | Nov 10, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an ... |
| CVE-2025-63710 | MEDIUM | 6.5 | 0.1% | Nov 10, 2025 | The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery ... |
| CVE-2025-63709 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text... |
| CVE-2025-12480 | CRITICAL | 9.1 | 90.4% | Nov 10, 2025 | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init... |
| CVE-2025-64690 | — | — | — | Nov 10, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it relates to interna... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now