2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66253 | CRITICAL | 9.8 | 2.1% | Nov 26, 2025 | Unauthenticated OS Command Injection (start_upgrade.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmitte... |
| CVE-2025-66251 | CRITICAL | 9.1 | 0.4% | Nov 26, 2025 | Unauthenticated Path Traversal with Arbitrary File Deletion in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-66250 | CRITICAL | 9.8 | 0.4% | Nov 26, 2025 | Unauthenticated Arbitrary File Upload (status_contents.php) in DB Electronica Telecomunicazioni S.p.A. Mozart FM Transmi... |
| CVE-2025-64657 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | Stack-based buffer overflow in Azure Application Gateway allows an unauthorized attacker to elevate privileges over a ne... |
| CVE-2025-64656 | CRITICAL | 9.8 | 0.5% | Nov 26, 2025 | Out-of-bounds read in Application Gateway allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2025-13597 | CRITICAL | 9.8 | 0.9% | Nov 25, 2025 | The AI Feeds plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actual... |
| CVE-2025-13595 | CRITICAL | 9.8 | 0.9% | Nov 25, 2025 | The CIBELES AI plugin for WordPress is vulnerable to arbitrary file uploads due to missing capability check in the 'actu... |
| CVE-2025-58360 | CRITICAL | 9.8 | 66.8% | Nov 25, 2025 | GeoServer is an open source server that allows users to share and edit geospatial data. From version 2.26.0 to before 2.... |
| CVE-2025-51746 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /serialNumber/addSerialNumber endpoint is vulnerable to fastjso... |
| CVE-2025-51745 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /role/addcan endpoint is vulnerable to fastjson deserialization... |
| CVE-2025-51744 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /user/addUser endpoint is vulnerable to fastjson deserializatio... |
| CVE-2025-51743 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /materialCategory/addMaterialCategory endpoint is vulnerable to... |
| CVE-2025-66016 | CRITICAL | 9.3 | 0.2% | Nov 25, 2025 | CGGMP24 is a state-of-art ECDSA TSS protocol that supports 1-round signing (requires 3 preprocessing rounds), identifiab... |
| CVE-2025-51742 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | An issue was discovered in jishenghua JSH_ERP 2.3.1. The /material/getMaterialEnableSerialNumberList endpoint passes the... |
| CVE-2025-64063 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 API endpoints fail to enforce sufficient authorization checks when processing requests. Specif... |
| CVE-2025-61168 | CRITICAL | 9.8 | 0.5% | Nov 25, 2025 | An issue in the cms_rest.php component of SIGB PMB v8.0.1.14 allows attackers to execute arbitrary code via unserializin... |
| CVE-2025-65085 | CRITICAL | 9.8 | 0.4% | Nov 25, 2025 | A Heap-based Buffer Overflow vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v... |
| CVE-2025-65084 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share version... |
| CVE-2025-63729 | CRITICAL | 9 | 0.1% | Nov 25, 2025 | An issue was discovered in Syrotech SY-GPON-1110-WDONT SYRO_3.7L_3.1.02-240517 allowing attackers to exctract the SSL Pr... |
| CVE-2025-60739 | CRITICAL | 9.6 | 0.3% | Nov 25, 2025 | Cross Site Request Forgery (CSRF) vulnerability in Ilevia EVE X1 Server Firmware Version v4.7.18.0.eden and before, Logi... |
| CVE-2025-64693 | CRITICAL | 9.8 | 0.6% | Nov 25, 2025 | Security Point (Windows) of MaLion and MaLionCloud contains a heap-based buffer overflow vulnerability in processing Con... |
| CVE-2025-62691 | CRITICAL | 9.8 | 0.6% | Nov 25, 2025 | Security Point (Windows) of MaLion and MaLionCloud contains a stack-based buffer overflow vulnerability in processing HT... |
| CVE-2025-59366 | CRITICAL | 9.2 | 15.1% | Nov 25, 2025 | An authentication-bypass vulnerability exists in AiCloud. This vulnerability can be triggered by an unintended side effe... |
| CVE-2025-13559 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. ... |
| CVE-2025-6389 | CRITICAL | 9.8 | 43.4% | Nov 25, 2025 | The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now