2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63289 | CRITICAL | 9.1 | 0.2% | Nov 12, 2025 | Sogexia Android App Compile Affected SDK v35, Max SDK 32 and fixed in v36, was discovered to contain hardcoded encryptio... |
| CVE-2025-11367 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization |
| CVE-2025-11366 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | N-central < 2025.4 is vulnerable to authentication bypass via path traversal |
| CVE-2025-63666 | CRITICAL | 9.8 | 0.4% | Nov 12, 2025 | Tenda AC15 v15.03.05.18_multi) issues an authentication cookie that exposes the account password hash to the client and ... |
| CVE-2025-40176 | CRITICAL | 9.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: tls: wait for pending async decryptions if tls_strp... |
| CVE-2025-12871 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to c... |
| CVE-2025-12870 | CRITICAL | 9.8 | 0.6% | Nov 12, 2025 | The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to s... |
| CVE-2025-60724 | CRITICAL | 9.8 | 5.8% | Nov 11, 2025 | Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code over a networ... |
| CVE-2025-13026 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F... |
| CVE-2025-13024 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 145 and Thunderbird ... |
| CVE-2025-13023 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F... |
| CVE-2025-13022 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-13021 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-8324 | CRITICAL | 9.8 | 1.5% | Nov 11, 2025 | Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the ... |
| CVE-2025-12539 | CRITICAL | 10 | 0.9% | Nov 11, 2025 | The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2025-12813 | CRITICAL | 9.8 | 0.7% | Nov 11, 2025 | The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2025-11457 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privile... |
| CVE-2025-11170 | CRITICAL | 9.8 | 0.7% | Nov 11, 2025 | The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
| CVE-2025-42890 | CRITICAL | 10 | 0.6% | Nov 11, 2025 | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended use... |
| CVE-2025-42887 | CRITICAL | 9.9 | 0.5% | Nov 11, 2025 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal... |
| CVE-2025-11892 | CRITICAL | 9.6 | 0.6% | Nov 10, 2025 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross... |
| CVE-2025-64513 | CRITICAL | 9.3 | 1.0% | Nov 10, 2025 | Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a... |
| CVE-2025-12480 | CRITICAL | 9.1 | 90.4% | Nov 10, 2025 | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init... |
| CVE-2025-12939 | CRITICAL | 9.8 | 0.3% | Nov 10, 2025 | A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is s... |
| CVE-2025-12938 | CRITICAL | 9.8 | 0.4% | Nov 10, 2025 | A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now