2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40934 | CRITICAL | 9.3 | 0.1% | Nov 26, 2025 | XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can ... |
| CVE-2025-65276 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | An unauthenticated administrative access vulnerability exists in the open-source HashTech project (https://github.com/he... |
| CVE-2025-50433 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | An issue was discovered in imonnit.com (2025-04-24) allowing malicious actors to gain escalated privileges via crafted p... |
| CVE-2025-65669 | CRITICAL | 9.1 | 0.5% | Nov 26, 2025 | An issue was discovered in classroomio 0.1.13. Student accounts are able to delete courses from the Explore page without... |
| CVE-2025-26155 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability... |
| CVE-2025-64130 | CRITICAL | 9.8 | 0.9% | Nov 26, 2025 | Zenitel TCIV-3+ is vulnerable to a reflected cross-site scripting vulnerability, which could allow a remote attacker to... |
| CVE-2025-64128 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to incomplete validation of user-supplied input. Validation fails to e... |
| CVE-2025-64127 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application a... |
| CVE-2025-64126 | CRITICAL | 10 | 2.3% | Nov 26, 2025 | An OS command injection vulnerability exists due to improper input validation. The application accepts a parameter dire... |
| CVE-2025-55469 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Incorrect access control in youlai-boot v2.21.1 allows attackers to escalate privileges and access the Administrator bac... |
| CVE-2025-65236 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | OpenCode Systems USSD Gateway OC Release: 5 was discovered to contain a SQL injection vulnerability via the Session ID p... |
| CVE-2025-65235 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | OpenCode Systems USSD Gateway OC Release: 5 Version 6.13.11 was discovered to contain a SQL injection vulnerability via ... |
| CVE-2025-62354 | CRITICAL | 9.8 | 1.2% | Nov 26, 2025 | Improper neutralization of special elements used in an OS command ('command injection') in Cursor allows an unauthorized... |
| CVE-2025-50402 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter string fac... |
| CVE-2025-50399 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | FAST FAC1200R F400_FAC1200R_Q is vulnerable to Buffer Overflow in the function sub_80435780 via the parameter password. |
| CVE-2025-59390 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSign... |
| CVE-2025-66022 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to version 1.7.1, an extension execution pa... |
| CVE-2025-66266 | CRITICAL | 9.3 | 0.1% | Nov 26, 2025 | The RupsMon.exe service executable in UPSilon 2000 has insecure permissions, allowing the 'Everyone' group Full Control.... |
| CVE-2025-66262 | CRITICAL | 9.8 | 1.2% | Nov 26, 2025 | Arbitrary File Overwrite via Tar Extraction Path Traversal in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit... |
| CVE-2025-66261 | CRITICAL | 9.8 | 2.1% | Nov 26, 2025 | Unauthenticated OS Command Injection (restore_settings.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66259 | CRITICAL | 9.8 | 0.6% | Nov 26, 2025 | Authenticated Root Remote Code Execution via improrer user input filtering in DB Electronica Telecomunicazioni S.p.A. Mo... |
| CVE-2025-66257 | CRITICAL | 9.1 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Deletion (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm... |
| CVE-2025-66256 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (patch_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmit... |
| CVE-2025-66255 | CRITICAL | 9.8 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transm... |
| CVE-2025-66254 | CRITICAL | 9.1 | 0.3% | Nov 26, 2025 | Unauthenticated Arbitrary File Deletion (upgrade_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Tran... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now