2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64433 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered... |
| CVE-2025-37736 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can... |
| CVE-2025-63420 | MEDIUM | 4.1 | 0.2% | Nov 7, 2025 | CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created F... |
| CVE-2025-60574 | HIGH | 7.5 | 0.4% | Nov 7, 2025 | A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles... |
| CVE-2025-12418 | MEDIUM | 5.6 | 0.1% | Nov 7, 2025 | Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2,... |
| CVE-2025-64481 | LOW | 2.7 | 0.4% | Nov 7, 2025 | Datasette is an open source multi-tool for exploring and publishing data. In versions 0.65.1 and below and 1.0a0 through... |
| CVE-2025-64442 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | HumHub is an Open Source Enterprise Social Network. Versions below 1.17.4 have a XSS vulnerability in the Meta-Search fe... |
| CVE-2025-64439 | HIGH | 7.4 | 0.9% | Nov 7, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2025-63544 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in /order_notes via the id parameter. |
| CVE-2025-63543 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS) in the /search_results endpoint via the q parameter. |
| CVE-2025-12902 | MEDIUM | 4.4 | 0.1% | Nov 7, 2025 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces... |
| CVE-2025-12896 | MEDIUM | 4.4 | 0.1% | Nov 7, 2025 | Improper resource management in firmware of some Solidigm DC Products may allow an attacker with local or physical acces... |
| CVE-2025-12875 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems... |
| CVE-2025-12863 | — | — | — | Nov 7, 2025 | Rejected reason: This CVE was assigned for a libxml2 issue#1012 but later deemed not valid. Ref.: https://gitlab.gnome.o... |
| CVE-2025-63640 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Sourcecodester Medicine Reminder App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Medicine Name" and "Notes ... |
| CVE-2025-63639 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting ... |
| CVE-2025-63638 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | Sourcecodester AI-Powered To-Do List App v1.0 is vulnerable to Cross-Site Scripting (XSS) in the "Task Title" and "Descr... |
| CVE-2025-10230 | CRITICAL | 10 | 39.7% | Nov 7, 2025 | A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a ... |
| CVE-2025-7700 | MEDIUM | 5.3 | 0.3% | Nov 7, 2025 | A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This ca... |
| CVE-2025-64432 | MEDIUM | 4.7 | 0.1% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. Versions 1.5.3 and below, and 1.6.0 contained a flawed i... |
| CVE-2025-64431 | HIGH | 8.7 | 0.3% | Nov 7, 2025 | Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direc... |
| CVE-2025-63717 | MEDIUM | 6.5 | 0.1% | Nov 7, 2025 | The change password functionality at /pet_grooming/admin/change_pass.php in SourceCodester Pet Grooming Management Softw... |
| CVE-2025-61261 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A reflected cross-site scripting (XSS) vulnerability in CKeditor v46.1.0 & Angular v18.0.0 allows attackers to execute a... |
| CVE-2025-36186 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations co... |
| CVE-2025-36185 | MEDIUM | 5.5 | 0.1% | Nov 7, 2025 | IBM Db2 12.1.0 through 12.1.2 for Linux, UNIX and Windows (includes Db2 Connect Server) could allow a local user to caus... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now