2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63783 | HIGH | 7.6 | 0.3% | Nov 7, 2025 | A Broken Object Level Authorization (BOLA) vulnerability was discovered in the tRPC project mutation APIs (update, delet... |
| CVE-2025-63691 | CRITICAL | 9.6 | 0.3% | Nov 7, 2025 | In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the... |
| CVE-2025-63690 | CRITICAL | 9.1 | 0.9% | Nov 7, 2025 | In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the sy... |
| CVE-2025-63689 | CRITICAL | 10 | 0.8% | Nov 7, 2025 | Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e... |
| CVE-2025-63687 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | An issue was discovered in rymcu forest thru commit f782e85 (2025-09-04) in function doBefore in file src/main/java/com/... |
| CVE-2025-63686 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | There is an arbitrary file download vulnerability in GuoMinJim PersonManage thru commit 5a02b1ab208feacf3a34fc123c938116... |
| CVE-2025-58469 | HIGH | 8.8 | 0.2% | Nov 7, 2025 | A cross-site request forgery (CSRF) vulnerability has been reported to affect QuLog Center. The remote attackers can the... |
| CVE-2025-58465 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Download Station. If a remote attacker gains a us... |
| CVE-2025-58464 | HIGH | 7.5 | 0.4% | Nov 7, 2025 | A relative path traversal vulnerability has been reported to affect QuMagie. If a remote attacker, they can then exploit... |
| CVE-2025-58463 | MEDIUM | 4.9 | 0.4% | Nov 7, 2025 | A relative path traversal vulnerability has been reported to affect Download Station. If a remote attacker gains an admi... |
| CVE-2025-57712 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, the... |
| CVE-2025-57706 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user... |
| CVE-2025-54168 | MEDIUM | 4.8 | 0.2% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect QuLog Center. If a remote attacker gains an admin... |
| CVE-2025-54167 | HIGH | 7.2 | 0.4% | Nov 7, 2025 | A cross-site scripting (XSS) vulnerability has been reported to affect Notification Center. If a remote attacker gains a... |
| CVE-2025-53413 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53412 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-53411 | MEDIUM | 4.9 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53410 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53409 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a r... |
| CVE-2025-53408 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-52865 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user a... |
| CVE-2025-52425 | CRITICAL | 9.8 | 0.4% | Nov 7, 2025 | An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to e... |
| CVE-2025-47207 | MEDIUM | 6.5 | 0.3% | Nov 7, 2025 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gain... |
| CVE-2025-12861 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability was determined in DedeBIZ up to 6.3.2. Affected by this vulnerability is an unknown functionality of the... |
| CVE-2025-12860 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability was found in DedeBIZ up to 6.3.2. Affected is an unknown function of the file /admin/freelist_main.php. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now