2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12913 | CRITICAL | 9.8 | 0.3% | Nov 8, 2025 | A flaw has been found in code-projects Responsive Hotel Site 1.0. This affects an unknown part of the file /admin/roomde... |
| CVE-2025-64486 | CRITICAL | 9.3 | 0.2% | Nov 8, 2025 | calibre is an e-book manager. In versions 8.13.0 and prior, calibre does not validate filenames when handling binary ass... |
| CVE-2025-10230 | CRITICAL | 10 | 39.7% | Nov 7, 2025 | A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a ... |
| CVE-2025-12873 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /a... |
| CVE-2025-3222 | CRITICAL | 9.3 | 0.5% | Nov 7, 2025 | Improper Authentication vulnerability in GE Vernova Smallworld on Windows, Linux allows Authentication Abuse.This issue ... |
| CVE-2025-12862 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A vulnerability was identified in projectworlds Online Notes Sharing Platform 1.0. Affected by this issue is some unknow... |
| CVE-2025-63691 | CRITICAL | 9.6 | 0.3% | Nov 7, 2025 | In pig-mesh In Pig version 3.8.2 and below, within the Token Management function under the System Management module, the... |
| CVE-2025-63690 | CRITICAL | 9.1 | 0.9% | Nov 7, 2025 | In pig-mesh Pig versions 3.8.2 and below, when setting up scheduled tasks in the Quartz management function under the sy... |
| CVE-2025-63689 | CRITICAL | 10 | 0.8% | Nov 7, 2025 | Multiple SQL injection vulnerabilitites in ycf1998 money-pos system before commit 11f276bd20a41f089298d804e43cb1c39d041e... |
| CVE-2025-52425 | CRITICAL | 9.8 | 0.4% | Nov 7, 2025 | An SQL injection vulnerability has been reported to affect QuMagie. A remote attacker can exploit the vulnerability to e... |
| CVE-2025-34299 | CRITICAL | 9.8 | 72.5% | Nov 7, 2025 | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This fl... |
| CVE-2025-12857 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow... |
| CVE-2025-12856 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /... |
| CVE-2025-12855 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi... |
| CVE-2025-12853 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele... |
| CVE-2025-10870 | CRITICAL | 9.3 | 0.2% | Nov 7, 2025 | SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete datab... |
| CVE-2025-64338 | CRITICAL | 9 | 0.4% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular use... |
| CVE-2025-12352 | CRITICAL | 9.8 | 0.7% | Nov 7, 2025 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-64180 | CRITICAL | 10 | 0.3% | Nov 7, 2025 | Manager-io/Manager is accounting software. In Manager Desktop and Server versions 25.11.1.3085 and below, a critical vul... |
| CVE-2025-11546 | CRITICAL | 9.3 | 0.4% | Nov 7, 2025 | CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, C... |
| CVE-2025-62630 | CRITICAL | 9.8 | 0.6% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories... |
| CVE-2025-59171 | CRITICAL | 9.8 | 0.6% | Nov 6, 2025 | Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories... |
| CVE-2025-12488 | CRITICAL | 9.8 | 0.8% | Nov 6, 2025 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This... |
| CVE-2025-12487 | CRITICAL | 9.8 | 0.8% | Nov 6, 2025 | oobabooga text-generation-webui trust_remote_code Reliance on Untrusted Inputs Remote Code Execution Vulnerability. This... |
| CVE-2025-27918 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now