2025 CVE Vulnerabilities
45,139 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13861 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scriptin... |
| CVE-2025-11775 | MEDIUM | 4.8 | 0.1% | Dec 17, 2025 | An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by ... |
| CVE-2025-13977 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2025-14801 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of th... |
| CVE-2025-11369 | MEDIUM | 4.3 | 0.3% | Dec 17, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to unau... |
| CVE-2025-11009 | MEDIUM | 5.1 | 0.1% | Dec 17, 2025 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all vers... |
| CVE-2025-34288 | MEDIUM | 6.7 | 1.8% | Dec 16, 2025 | Nagios XI versions prior to 2026R1.1 are vulnerable to local privilege escalation due to an unsafe interaction between s... |
| CVE-2025-64520 | MEDIUM | 4.3 | 0.2% | Dec 16, 2025 | GLPI is a free asset and IT management software package. Starting in version 9.1.0 and prior to version 10.0.21, an unau... |
| CVE-2025-14466 | MEDIUM | 6.9 | 0.3% | Dec 16, 2025 | A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthe... |
| CVE-2025-13532 | MEDIUM | 6.2 | 0.1% | Dec 16, 2025 | Insecure defaults in the Server Agent component of Fortra's Core Privileged Access Manager (BoKS) can result in the sele... |
| CVE-2025-68150 | MEDIUM | 6.5 | 0.3% | Dec 16, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2025-68146 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTO... |
| CVE-2025-65592 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) in the product management functionality. Malicious payloa... |
| CVE-2025-65591 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Currencies functionality. |
| CVE-2025-65590 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Blog posts functionality in the Content Managemen... |
| CVE-2025-68142 | MEDIUM | 5.3 | 0.4% | Dec 16, 2025 | PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a R... |
| CVE-2025-65589 | MEDIUM | 6.1 | 0.3% | Dec 16, 2025 | nopCommerce 4.90.0 is vulnerable to Cross Site Scripting (XSS) via the Attributes functionality. |
| CVE-2025-65581 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | An open redirect vulnerability exists in the Account module in Volosoft ABP Framework >= 5.1.0 and < 10.0.0-rc.2. Improp... |
| CVE-2025-46296 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privile... |
| CVE-2025-46294 | MEDIUM | 5.3 | 0.2% | Dec 16, 2025 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumerat... |
| CVE-2025-68116 | MEDIUM | 5.4 | 0.2% | Dec 16, 2025 | FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site ... |
| CVE-2025-62862 | MEDIUM | 4.6 | 0.1% | Dec 16, 2025 | Ampere AmpereOne AC03 devices before 3.5.9.3, AmpereOne AC04 devices before 4.4.5.2, and AmpereOne M devices before 5.4.... |
| CVE-2025-59935 | MEDIUM | 6.5 | 0.2% | Dec 16, 2025 | GLPI is a free asset and IT management software package. Starting in version 10.0.0 and prior to version 10.0.21, an una... |
| CVE-2025-29231 | MEDIUM | 6.1 | 0.2% | Dec 16, 2025 | A stored cross-site scripting (XSS) vulnerability in the page_save component of Linksys E5600 V1.1.0.26 allows attackers... |
| CVE-2025-68269 | MEDIUM | 5.4 | 0.1% | Dec 16, 2025 | In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now