2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64184 | HIGH | 8.8 | 0.4% | Nov 7, 2025 | Dosage is a comic strip downloader and archiver. When downloading comic images in versions 3.1 and below, Dosage constru... |
| CVE-2025-64180 | CRITICAL | 10 | 0.3% | Nov 7, 2025 | Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vul... |
| CVE-2025-5483 | HIGH | 8.1 | 0.3% | Nov 7, 2025 | The LC Wizard plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check in the ghl-wi... |
| CVE-2025-11546 | CRITICAL | 9.3 | 0.4% | Nov 7, 2025 | CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, C... |
| CVE-2025-52662 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A vulnerability in Nuxt DevTools has been fixed in version **2.6.4***. This issue may have allowed Nuxt auth token extra... |
| CVE-2025-48985 | MEDIUM | 5.3 | 0.2% | Nov 7, 2025 | A vulnerability in Vercel’s AI SDK has been fixed in versions 5.0.52, 5.1.0-beta.9, and 6.0.0-beta. This issue may have ... |
| CVE-2025-12789 | MEDIUM | 6.1 | 0.2% | Nov 7, 2025 | A flaw was found in Red Hat Single Sign-On. This issue is an Open Redirect vulnerability that occurs during the logout p... |
| CVE-2025-64302 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Insufficient input sanitization in the dashboard label or path can allow an attacker to trigger a device error causing ... |
| CVE-2025-62630 | CRITICAL | 9.8 | 0.6% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories... |
| CVE-2025-59171 | CRITICAL | 9.8 | 0.6% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories... |
| CVE-2025-58423 | HIGH | 8.8 | 0.5% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to cause a denial-of-se... |
| CVE-2025-12636 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | The Ubia camera ecosystem fails to adequately secure API credentials, potentially enabling an attacker to connect to ba... |
| CVE-2025-12036 | HIGH | 8.8 | 3.5% | Nov 6, 2025 | Out of bounds memory access in V8 in Google Chrome prior to 141.0.7390.122 allowed a remote attacker to perform out of b... |
| CVE-2025-11756 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | Use after free in Safe Browsing in Google Chrome prior to 141.0.7390.107 allowed a remote attacker who had compromised t... |
| CVE-2025-11460 | HIGH | 8.8 | 0.3% | Nov 6, 2025 | Use after free in Storage in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to execute arbitrary code vi... |
| CVE-2025-11458 | HIGH | 8.1 | 0.3% | Nov 6, 2025 | Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of boun... |
| CVE-2025-64179 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | lakeFS is an open-source tool that transforms object storage into a Git-like repositories. In versions 1.69.0 and below,... |
| CVE-2025-64178 | HIGH | 8.9 | 0.3% | Nov 6, 2025 | Jellysweep is a cleanup tool for the Jellyfin media server. In versions 0.12.1 and below, /api/images/cache, used to dow... |
| CVE-2025-64177 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, th... |
| CVE-2025-64176 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | ThinkDashboard is a self-hosted bookmark dashboard built with Go and vanilla JavaScript. In versions 0.6.7 and below, an... |
| CVE-2025-11219 | LOW | 3.1 | 0.2% | Nov 6, 2025 | Use after free in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to potentially perform out of bou... |
| CVE-2025-11216 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Storage in Google Chrome on Mac prior to 141.0.7390.54 allowed a remote attacker to perf... |
| CVE-2025-11215 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | Off by one error in V8 in Google Chrome prior to 141.0.7390.54 allowed a remote attacker to perform an out of bounds mem... |
| CVE-2025-11213 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Omnibox in Google Chrome on Android prior to 141.0.7390.54 allowed a remote attacker who... |
| CVE-2025-11212 | MEDIUM | 6.3 | 0.2% | Nov 6, 2025 | Inappropriate implementation in Media in Google Chrome on Windows prior to 141.0.7390.54 allowed a remote attacker who c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now