Vulnerability Report - November 2025

All vulnerability reports

Introduction

This vulnerability report has been generated using data aggregated on Vulnerability-Lookup, with contributions from the platform’s community.

It highlights the most frequently mentioned vulnerability for November 2025, based on sightings collected from various sources, including MISP, Exploit-DB, Bluesky, Mastodon, GitHub Gists, The Shadowserver Foundation, Nuclei, SPLOITUS, Metasploit, and more. For further details, please visit this page.

The Month at a Glance

The most frequently sighted vulnerability in November was CVE-2025-64446 (105 sightings), a Critical-severity vulnerability in Fortinet FortiWeb. Fortinet featured prominently, with a second FortiWeb vulnerability, CVE-2025-58034 (High severity), also in the top 10.

Other critical vulnerabilities in the top 10 include CVE-2025-59287 in Microsoft Windows Server 2019 (88 sightings) and CVE-2025-61757 in Oracle Corporation Identity Manager (67 sightings). The list also features a highly sighted vulnerability in Samsung Mobile Devices (CVE-2025-21042), a High-severity flaw in Google Chrome (CVE-2025-13223), and an older but still active vulnerability in Cisco IOS XE Software (CVE-2023-20198).

November saw 11 new entries added to the CISA Known Exploited Vulnerabilities catalog, highlighting actively exploited threats. Notable additions include:

No new entries were added to the ENISA KEV catalog in November.

The report also details vulnerabilities that have reserved CVE IDs but have limited public information, showing early sightings detected on the internet. CVE-2023-42344 and CVE-2025-13086 were the most sighted in this category, each with 6 occurrences.

In addition, contributor insights covered topics like RCE in Agent DVR, an APT exploiting Cisco and Citrix zero-days discovered by Amazon, and the UNC6148 Backdoors utilizing the OVERSTEP Rootkit on SonicWall SMA 100 Series Devices.

Evolution of published CVE in 2025

Evolution of published CVE in 2025

More information.

Top 10 Vendors of the Month

Top 10 Vendors of the Month

Top 10 Assigners of the Month

Top 10 Assigners of the Month

Top 10 vulnerabilities of the Month

VulnerabilitySighting CountVendorProductVLAI Severity
CVE-2025-64446105FortinetFortiWebCritical (confidence: 0.9084)
CVE-2025-5928788MicrosoftWindows Server 2019Critical (confidence: 0.9565)
CVE-2025-2104286Samsung MobileSamsung Mobile DevicesHigh (confidence: 0.9308)
CVE-2025-5803484FortinetFortiWebHigh (confidence: 0.9584)
CVE-2025-1322384GoogleChromeHigh (confidence: 0.9675)
CVE-2023-2019871CiscoCisco IOS XE SoftwareHigh (confidence: 0.9908)
CVE-2025-6175767Oracle CorporationIdentity ManagerCritical (confidence: 0.9961)
CVE-2025-11001657-Zip7-ZipHigh (confidence: 0.9967)
CVE-2025-124864TrioFoxTrioFoxCritical (confidence: 0.4751)
CVE-2015-205159dlinkdir-645High (confidence: 0.744)

Except CVE-2025-11001, all listed vulnerabilities are in CISA.

Sightings forecast

The following visualizations represent the forecasted number of sightings for various vulnerabilities, using an adaptive model (decay or logistic growth), with vulnerabilities selected based on having a sufficient number of sightings and relatively consistent patterns.

Forecast CVE-2015-2051

Forecast CVE-2023-20198

Forecast CVE-2025-59287

Forecast CVE-2025-64446

Known Exploited Vulnerabilities

New entries have been added to major Known Exploited Vulnerabilities catalogs.

CISA

CVE IDDate AddedVendorProductVLAI Severity
CVE-2025-4870304/11/25centos-webpanelCentOS Web PanelCritical (confidence: 0.9836)
CVE-2025-1137104/11/25GladinetCentreStack and TrioFoxMedium (confidence: 0.9575)
CVE-2025-2104210/11/25Samsung MobileSamsung Mobile DevicesHigh (confidence: 0.9308)
CVE-2025-924212/11/25WatchGuardFireware OSCritical (confidence: 0.9381)
CVE-2025-6221512/11/25MicrosoftWindows 10 Version 1809High (confidence: 0.9918)
CVE-2025-1248012/11/25TrioFoxTrioFoxCritical (confidence: 0.4751)
CVE-2025-6444614/11/25FortinetFortiWebCritical (confidence: 0.9084)
CVE-2025-5803418/11/25FortinetFortiWebHigh (confidence: 0.9584)
CVE-2025-1322319/11/25GoogleChromeHigh (confidence: 0.9675)
CVE-2025-6175721/11/25Oracle CorporationIdentity ManagerCritical (confidence: 0.9961)
CVE-2021-2682928/11/25scadabrscadabrMedium (confidence: 0.9951)

ENISA

No new entry in November.

Top 10 Weaknesses of the Month

Top 10 Weaknesses of the Month

Click the image for more information.

CVE reserved, but partial information has already appeared on the public internet

Sightings detected between 2025-11-01 and 2025-11-30 that are associated with vulnerabilities without public records.

Vulnerability IDOccurrencesComment
CVE-2025-593967Not a security vulnerability (GCVE - watchguard / firebox).
CVE-2023-423446source: The Shadowserver (honeypot/common-vulnerabilities)
CVE-2025-130866OpenVPN
CVE-2025-662705KDE Connect
CVE-2025-1100257-Zip
CVE-2025-98204gnutls
CVE-2025-126863BeeStation
CVE-2024-91832Race condition issue in CI/CD cache impacts GitLab CE/EE
CVE-2025-131672Synology
CVE-2025-133922Synology
CVE-2025-135932Synology
CVE-2025-136992mariadb-dump Utility
CVE-2020-231252Vulncheck KEV
GHSA-x697-jf34-gp5x3Wazuh Agent (v4.10.1)
CVE-2024-10451GRUB 2
CVE-2025-362701Fedora 42 Kubernetes
CVE-2025-288401Fedora 42 Kubernetes
CVE-2024-244811Tenda 4G03 Pro and N300 Routers
CVE-2024-593731ASUS
CVE-2025-123451SUSE Linux Enterprise Server (SLES) security patch
CVE-2025-132071Tenda 4G03 Pro and N300 Routers
CVE-2025-136981Deciso OPNsense
CVE-2025-137001DreamFactory saveZipFile
CVE-2025-137031VIPRE Advanced Security
CVE-2025-211401Oracle Linux 8
CVE-2025-303331Federal civilian agencies are failing to adequately patch vulnerable Cisco devices amid ongoing exploitation
CVE-2025-335141W3 Total Cache WordPress plugin
CVE-2025-335151
CVE-2025-444461Fortiweb
CVE-2025-520221emsloyalty backend
CVE-2025-520231gemscms backend
CVE-2025-520241gemscms POS Platform (backend)
CVE-2025-520251gemscms backend (POS platform)
CVE-2025-520261gemscms backend (POS platform)
CVE-2025-583881Android: Vulnerability-Lookup bundle
CVE-2025-583901Android: Vulnerability-Lookup bundle
CVE-2025-583921Android: Vulnerability-Lookup bundle
CVE-2025-583941Android: Vulnerability-Lookup bundle
CVE-2025-583961Android: Vulnerability-Lookup bundle
CVE-2025-583971Android: cVulnerability-Lookup bundle
CVE-2025-5936561ASUS
CVE-2025-602741Windows graphic component (GDI+)
CVE-2025-637211HummerRisk
CVE-2025-658821OpenMPTCProuter

Insights from Contributors

Thank you

Thank you to all the contributors and our diverse sources!

If you want to contribute to the next report, you can create your account.

Feedback and Support

If you have suggestions, please feel free to open a ticket on our GitHub repository. Your feedback is invaluable to us!
https://github.com/vulnerability-lookup/vulnerability-lookup/issues/

Funding

eu_funded_en

The main objective of Federated European Team for Threat Analysis (FETTA) is improvement of Cyber Threat Intelligence (CTI) products available to the public and private sector in Poland, Luxembourg, and the European Union as a whole.
Developing actionable CTI products (reports, indicators, etc) is a complex task and requires an in-depth understanding of the threat landscape and the ability to analyse and interpret large amounts of data. Many SOCs and CSIRTs build their capabilities in this area independently, leading to a fragmented approach and duplication of work.

The Computer Incident Response Center Luxembourg (CIRCL) is a government-driven initiative designed to provide a systematic response facility to computer security threats and incidents. The organization brings to the table its extensive experience in cybersecurity incident management, threat intelligence, and proactive response strategies. With a strong background in developing innovative open source cybersecurity tools and solutions, CIRCL’s contribution to the FETTA project is instrumental in achieving enhanced collaboration and intelligence sharing across Europe.

Press release