2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59716 | MEDIUM | 5.3 | 0.9% | Nov 5, 2025 | ownCloud Guests before 0.12.5 allows unauthenticated user enumeration via the /apps/guests/register/{email}/{token} endp... |
| CVE-2025-57244 | MEDIUM | 5.4 | 0.2% | Nov 5, 2025 | OpenKM Community Edition 6.3.12 is vulnerable to stored cross-site scripting (XSS) in the user account creation interfac... |
| CVE-2025-46424 | MEDIUM | 4.4 | 0.1% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain use of a Cryptographic Primitive with a Risky Implementation vulnerabilit... |
| CVE-2025-46366 | MEDIUM | 6.7 | 0.1% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user may exploit and gain parallel p... |
| CVE-2025-46365 | MEDIUM | 6.7 | 0.4% | Nov 5, 2025 | Dell CloudLink, versions prior 8.1.1, contain a Command Injection vulnerability which can be exploited by an Authenticat... |
| CVE-2025-46364 | HIGH | 7.2 | 0.3% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.1.1, contain a vulnerability where a privileged user with known password can run CLI... |
| CVE-2025-45379 | HIGH | 8.4 | 0.7% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma... |
| CVE-2025-45378 | CRITICAL | 9.1 | 0.3% | Nov 5, 2025 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass... |
| CVE-2025-43990 | HIGH | 7.8 | 0.1% | Nov 5, 2025 | Dell Command Monitor (DCM), versions prior to 10.12.3.28, contains an Execution with Unnecessary Privileges vulnerabilit... |
| CVE-2025-30479 | HIGH | 7.2 | 1.1% | Nov 5, 2025 | Dell CloudLink, versions prior to 8.2, contain a vulnerability where a privileged user with known password can run comma... |
| CVE-2025-20377 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker ... |
| CVE-2025-20376 | HIGH | 7.2 | 0.4% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a... |
| CVE-2025-20375 | HIGH | 7.2 | 0.3% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to upload and execute a... |
| CVE-2025-20374 | MEDIUM | 4.9 | 0.9% | Nov 5, 2025 | A vulnerability in the web UI of Cisco Unified CCX could allow an authenticated, remote attacker to perform a directory ... |
| CVE-2025-20358 | CRITICAL | 9.8 | 0.9% | Nov 5, 2025 | A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticat... |
| CVE-2025-20354 | CRITICAL | 9.8 | 0.8% | Nov 5, 2025 | A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, ... |
| CVE-2025-20343 | HIGH | 7.5 | 0.7% | Nov 5, 2025 | A vulnerability in the RADIUS setting Reject RADIUS requests from clients with repeated failures on Cisco Identity Servi... |
| CVE-2025-20305 | MEDIUM | 4.9 | 0.3% | Nov 5, 2025 | A vulnerability in the web-based management interface of Cisco ISE could allow an authenticated, remote attacker to obta... |
| CVE-2025-20304 | MEDIUM | 5.4 | 0.2% | Nov 5, 2025 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat... |
| CVE-2025-20303 | MEDIUM | 5.4 | 3.1% | Nov 5, 2025 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat... |
| CVE-2025-20289 | MEDIUM | 5.4 | 0.2% | Nov 5, 2025 | Multiple vulnerabilities in the web-based management interface of Cisco ISE and Cisco ISE-PIC could allow an authenticat... |
| CVE-2025-63601 | CRITICAL | 9.9 | 0.5% | Nov 5, 2025 | Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to up... |
| CVE-2025-61304 | CRITICAL | 9.8 | 1.8% | Nov 5, 2025 | OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. |
| CVE-2025-60753 | MEDIUM | 5.5 | 0.1% | Nov 5, 2025 | An issue was discovered in libarchive bsdtar before version 3.8.1 in function apply_substitution in file tar/subst.c whe... |
| CVE-2025-57130 | HIGH | 8.8 | 0.4% | Nov 5, 2025 | An Incorrect Access Control vulnerability in the user management component of ZwiiCMS up to v13.6.07 allows a remote, au... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now