2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59390 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign... |
| CVE-2025-66022 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa... |
| CVE-2025-66266 | CRITICAL | 9.3 | 0.1% | Nov 26, 2025 | The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control.... |
| CVE-2025-66262 | CRITICAL | 9.8 | 1.2% | Nov 26, 2025 | Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit... |
| CVE-2025-66261 | CRITICAL | 9.8 | 2.1% | Nov 26, 2025 | Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66259 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo... |
| CVE-2025-66257 | CRITICAL | 9.1 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm... |
| CVE-2025-66256 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit... |
| CVE-2025-66255 | CRITICAL | 9.8 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm... |
| CVE-2025-66254 | CRITICAL | 9.1 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran... |
| CVE-2025-66253 | CRITICAL | 9.8 | 2.1% | Nov 26, 2025 | Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte... |
| CVE-2025-66251 | CRITICAL | 9.1 | 0.4% | Nov 26, 2025 | Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66250 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-64657 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2025-64656 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-13597 | CRITICAL | 9.8 | 0.9% | Nov 25, 2025 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual... |
| CVE-2025-13595 | CRITICAL | 9.8 | 0.9% | Nov 25, 2025 | The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu... |
| CVE-2025-58360 | CRITICAL | 9.8 | 66.8% | Nov 25, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.... |
| CVE-2025-51746 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjso... |
| CVE-2025-51745 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization... |
| CVE-2025-51744 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserializatio... |
| CVE-2025-51743 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to... |
| CVE-2025-66016 | CRITICAL | 9.3 | 0.2% | Nov 25, 2025 | CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab... |
| CVE-2025-51742 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the... |
| CVE-2025-64063 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now