2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62596 | CRITICAL | 10 | 0.2% | Nov 6, 2025 | Youki is a container runtime written in Rust. In versions 0.5.6 and below, youki’s apparmor handling performs insufficie... |
| CVE-2025-62161 | CRITICAL | 10 | 0.2% | Nov 6, 2025 | Youki is a container runtime written in Rust. In versions 0.5.6 and below, the initial validation of the source /dev/nul... |
| CVE-2025-63334 | CRITICAL | 9.8 | 1.1% | Nov 5, 2025 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the subm... |
| CVE-2025-63416 | CRITICAL | 9.1 | 0.3% | Nov 5, 2025 | ** exclusively-hosted-service ** A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the Self... |
| CVE-2025-55343 | CRITICAL | 9.9 | 0.5% | Nov 5, 2025 | Quipux 4.0.1 through e1774ac allows authenticated users to conduct SQL injection attacks via busqueda/busqueda.php txt_d... |
| CVE-2025-56231 | CRITICAL | 9.1 | 0.2% | Nov 5, 2025 | Tonec Internet Download Manager 6.42.41.1 and earlier suffers from Missing SSL Certificate Validation, which allows atta... |
| CVE-2025-10713 | CRITICAL | 9.1 | 0.4% | Nov 5, 2025 | An XML External Entity (XXE) vulnerability exists in multiple WSO2 products due to improper configuration of the XML par... |
| CVE-2025-45378 | CRITICAL | 9.1 | 0.3% | Nov 5, 2025 | Dell CloudLink, versions 8.0 through 8.1.2, contain vulnerability on restricted shell. A Privileged user with known pass... |
| CVE-2025-20358 | CRITICAL | 9.8 | 0.9% | Nov 5, 2025 | A vulnerability in the Contact Center Express (CCX) Editor application of Cisco Unified CCX could allow an unauthenticat... |
| CVE-2025-20354 | CRITICAL | 9.8 | 0.8% | Nov 5, 2025 | A vulnerability in the Java Remote Method Invocation (RMI) process of Cisco Unified CCX could allow an unauthenticated, ... |
| CVE-2025-63601 | CRITICAL | 9.9 | 0.5% | Nov 5, 2025 | Snipe-IT before version 8.3.3 contains a remote code execution vulnerability that allows an authenticated attacker to up... |
| CVE-2025-61304 | CRITICAL | 9.8 | 1.8% | Nov 5, 2025 | OS command injection vulnerability in Dynatrace ActiveGate ping extension up to 1.016 via crafted ip address. |
| CVE-2025-64459 | CRITICAL | 9.1 | 19.1% | Nov 5, 2025 | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, ... |
| CVE-2025-47151 | CRITICAL | 9.8 | 0.8% | Nov 5, 2025 | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 ... |
| CVE-2025-55108 | CRITICAL | 10 | 0.7% | Nov 5, 2025 | The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un... |
| CVE-2025-12674 | CRITICAL | 9.8 | 0.7% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-11749 | CRITICAL | 9.8 | 75.8% | Nov 5, 2025 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2025-12735 | CRITICAL | 9.8 | 2.2% | Nov 5, 2025 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio... |
| CVE-2025-52910 | CRITICAL | 9.8 | 0.3% | Nov 4, 2025 | An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 148... |
| CVE-2025-47776 | CRITICAL | 9.1 | 0.3% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===... |
| CVE-2025-12108 | CRITICAL | 9.3 | 0.4% | Nov 4, 2025 | The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration... |
| CVE-2025-61956 | CRITICAL | 9.8 | 0.7% | Nov 4, 2025 | Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access an... |
| CVE-2025-61945 | CRITICAL | 9.8 | 0.8% | Nov 4, 2025 | Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without auth... |
| CVE-2025-54863 | CRITICAL | 9.8 | 0.6% | Nov 4, 2025 | Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration f... |
| CVE-2025-12682 | CRITICAL | 9.8 | 0.5% | Nov 4, 2025 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now