2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64114 | MEDIUM | 6.5 | 0.4% | Nov 6, 2025 | ClipBucket v5 is an open source video sharing platform. Versions 5.5.2 - #151 and below allow authenticated administrato... |
| CVE-2025-62596 | CRITICAL | 10 | 0.2% | Nov 6, 2025 | Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie... |
| CVE-2025-62161 | CRITICAL | 10 | 0.2% | Nov 6, 2025 | Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul... |
| CVE-2025-55278 | HIGH | 8.1 | 0.2% | Nov 5, 2025 | Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep... |
| CVE-2025-12779 | HIGH | 8.8 | 0.2% | Nov 5, 2025 | Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,... |
| CVE-2025-63585 | MEDIUM | 6.5 | 0.2% | Nov 5, 2025 | OSSN (Open Source Social Network) 8.6 is vulnerable to SQL Injection in /action/rtcomments/status via the timestamp para... |
| CVE-2025-60784 | MEDIUM | 6.5 | 0.3% | Nov 5, 2025 | A vulnerability in the XiaozhangBang Voluntary Like System V8.8 allows remote attackers to manipulate the zhekou paramet... |
| CVE-2025-63334 | CRITICAL | 9.8 | 1.1% | Nov 5, 2025 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm... |
| CVE-2025-10853 | MEDIUM | 6.1 | 0.2% | Nov 5, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the management console of multiple WSO2 products due to i... |
| CVE-2025-63418 | MEDIUM | 6.1 | 0.2% | Nov 5, 2025 | A DOM-based Cross-Site Scripting (XSS) vulnerability in the SelfBest platform 2023.3 allows attackers to execute arbitra... |
| CVE-2025-63417 | HIGH | 7.2 | 0.2% | Nov 5, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authe... |
| CVE-2025-63416 | CRITICAL | 9.1 | 0.3% | Nov 5, 2025 | ** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the Self... |
| CVE-2025-5770 | MEDIUM | 6.1 | 0.2% | Nov 5, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the authentication endpoints of multiple WSO2 products du... |
| CVE-2025-56232 | MEDIUM | 6.8 | 0.1% | Nov 5, 2025 | GOG Galaxy 2.0.0.2 suffers from Missing SSL Certificate Validation. An attacker who controls the local network, DNS, or ... |
| CVE-2025-55343 | CRITICAL | 9.9 | 0.5% | Nov 5, 2025 | Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d... |
| CVE-2025-55342 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | Quipux 4.0.1 through e1774ac allows enumeration of usernames, and accessing the Ecuadorean identification number for all... |
| CVE-2025-55341 | MEDIUM | 6.5 | 0.2% | Nov 5, 2025 | Cross Site Scripting vulnerability in Quipux 4.0.1 through e1774ac allows anexos/anexos_nuevo.php asocImgRad. |
| CVE-2025-43418 | MEDIUM | 4.6 | 0.2% | Nov 5, 2025 | This issue was addressed by restricting options offered on a locked device. This issue is fixed in iOS 18.7.2 and iPadOS... |
| CVE-2025-31954 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to pro... |
| CVE-2025-12745 | HIGH | 7.8 | 0.2% | Nov 5, 2025 | A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_a... |
| CVE-2025-11093 | HIGH | 7.2 | 0.4% | Nov 5, 2025 | An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal... |
| CVE-2025-56231 | CRITICAL | 9.1 | 0.2% | Nov 5, 2025 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta... |
| CVE-2025-10907 | HIGH | 7.2 | 0.5% | Nov 5, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to insufficient validation of uploaded conte... |
| CVE-2025-10713 | CRITICAL | 9.1 | 0.4% | Nov 5, 2025 | An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML par... |
| CVE-2025-63248 | HIGH | 7.5 | 0.3% | Nov 5, 2025 | DWSurvey 6.14.0 is vulnerable to Incorrect Access Control. When deleting a questionnaire, replacing the questionnaire ID... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now