2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34241 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDevice... |
| CVE-2025-34240 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgr... |
| CVE-2025-34239 | HIGH | 7.2 | 1.6% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.app... |
| CVE-2025-34238 | MEDIUM | 6.5 | 0.3% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsControlle... |
| CVE-2025-34237 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via Standalone... |
| CVE-2025-34236 | MEDIUM | 5.4 | 0.2% | Nov 6, 2025 | Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksCo... |
| CVE-2025-12490 | HIGH | 8.8 | 18.7% | Nov 6, 2025 | Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-63551 | HIGH | 7.5 | 0.4% | Nov 6, 2025 | A Server-Side Request Forgery (SSRF) vulnerability, achievable through an XML External Entity (XXE) injection, exists in... |
| CVE-2025-60541 | HIGH | 7.3 | 0.2% | Nov 6, 2025 | A Server-Side Request Forgery (SSRF) in the /api/proxy/ component of linshenkx prompt-optimizer v1.3.0 to v1.4.2 allows ... |
| CVE-2025-31133 | HIGH | 7.8 | 0.7% | Nov 6, 2025 | runc is a CLI tool for spawning and running containers according to the OCI specification. In versions 1.2.7 and below, ... |
| CVE-2025-22397 | MEDIUM | 4.9 | 0.4% | Nov 6, 2025 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions 6.10.80.00 thro... |
| CVE-2025-27919 | HIGH | 8.2 | 0.3% | Nov 6, 2025 | An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can ... |
| CVE-2025-27918 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.... |
| CVE-2025-27917 | HIGH | 7.5 | 0.4% | Nov 6, 2025 | An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.... |
| CVE-2025-27916 | HIGH | 7.5 | 0.3% | Nov 6, 2025 | An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection be... |
| CVE-2025-12815 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | An ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS ... |
| CVE-2025-63589 | HIGH | 7.1 | 0.3% | Nov 6, 2025 | A reflected XSS vulnerability exists in CMSimple_XH 1.8's index.php router when attacker-controlled path segments are no... |
| CVE-2025-63588 | HIGH | 7.1 | 0.3% | Nov 6, 2025 | An unauthenticated reflected cross-site scripting vulnerability in the query handling of CMSimpleXH allows remote attack... |
| CVE-2025-63560 | HIGH | 7.5 | 0.6% | Nov 6, 2025 | An issue in KiloView Dual Channel 4k HDMI & 3G-SDI HEVC Video Encoder Firmware v.1.20.0006 allows a remote attacker to c... |
| CVE-2025-59396 | — | — | — | Nov 6, 2025 | Rejected reason: Not a security vulnerability |
| CVE-2025-12808 | MEDIUM | 6.5 | 0.4% | Nov 6, 2025 | Improper access control in Devolutions allows a View-only user to retrieve sensitive third-level nested fields, such as ... |
| CVE-2025-12485 | HIGH | 8.8 | 0.6% | Nov 6, 2025 | Improper privilege management during pre-MFA cookie handling in Devolutions Server allows a low-privileged authenticated... |
| CVE-2025-10885 | HIGH | 7.8 | 0.1% | Nov 6, 2025 | A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYST... |
| CVE-2025-6327 | CRITICAL | 10 | 0.5% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in KingAddons.com King Addons for Elementor king-addons al... |
| CVE-2025-6325 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Incorrect Privilege Assignment vulnerability in KingAddons.com King Addons for Elementor king-addons allows Privilege Es... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now