2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-53283 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in borisolhor Drop Uploader for CF7 - Drag&Drop File Uploa... |
| CVE-2025-53242 | CRITICAL | 9.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in VictorThemes Seil seil allows Object Injection.This issue affects Sei... |
| CVE-2025-52773 | CRITICAL | 9.3 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiecor HieCOR Paym... |
| CVE-2025-49393 | CRITICAL | 9.8 | 0.5% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Object Injection.T... |
| CVE-2025-49372 | CRITICAL | 10 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in VillaTheme HAPPY happy-helpdesk-support-ticke... |
| CVE-2025-48089 | CRITICAL | 9.3 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Rainbow-Themes Edu... |
| CVE-2025-47588 | CRITICAL | 9.1 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in acowebs Dynamic Pricing With Discount Rules f... |
| CVE-2025-32222 | CRITICAL | 9.9 | 0.4% | Nov 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic all... |
| CVE-2025-64164 | CRITICAL | 9.8 | 0.5% | Nov 6, 2025 | Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly fi... |
| CVE-2025-64163 | CRITICAL | 9.8 | 1.0% | Nov 6, 2025 | DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist... |
| CVE-2025-62596 | CRITICAL | 10 | 0.2% | Nov 6, 2025 | Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie... |
| CVE-2025-62161 | CRITICAL | 10 | 0.2% | Nov 6, 2025 | Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul... |
| CVE-2025-63334 | CRITICAL | 9.8 | 1.1% | Nov 5, 2025 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm... |
| CVE-2025-63416 | CRITICAL | 9.1 | 0.3% | Nov 5, 2025 | ** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the Self... |
| CVE-2025-55343 | CRITICAL | 9.9 | 0.5% | Nov 5, 2025 | Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d... |
| CVE-2025-56231 | CRITICAL | 9.1 | 0.2% | Nov 5, 2025 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta... |
| CVE-2025-10713 | CRITICAL | 9.1 | 0.4% | Nov 5, 2025 | An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML par... |
| CVE-2025-45378 | CRITICAL | 9.1 | 0.3% | Nov 5, 2025 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass... |
| CVE-2025-20358 | CRITICAL | 9.8 | 0.9% | Nov 5, 2025 | A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticat... |
| CVE-2025-20354 | CRITICAL | 9.8 | 0.8% | Nov 5, 2025 | A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, ... |
| CVE-2025-63601 | CRITICAL | 9.9 | 0.5% | Nov 5, 2025 | Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to up... |
| CVE-2025-61304 | CRITICAL | 9.8 | 1.8% | Nov 5, 2025 | OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. |
| CVE-2025-64459 | CRITICAL | 9.1 | 19.1% | Nov 5, 2025 | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, ... |
| CVE-2025-47151 | CRITICAL | 9.8 | 0.8% | Nov 5, 2025 | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 ... |
| CVE-2025-55108 | CRITICAL | 10 | 0.7% | Nov 5, 2025 | The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now