2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14068 | HIGH | 7.5 | 0.3% | Dec 12, 2025 | The WPNakama plugin for WordPress is vulnerable to time-based SQL Injection via the 'order_by' parameter in all versions... |
| CVE-2025-12570 | HIGH | 7.2 | 0.2% | Dec 12, 2025 | The Fancy Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all... |
| CVE-2025-67725 | HIGH | 7.5 | 0.4% | Dec 12, 2025 | Tornado is a Python web framework and asynchronous networking library. In versions 6.5.2 and below, a single maliciously... |
| CVE-2025-67508 | HIGH | 8.4 | 0.2% | Dec 12, 2025 | gardenctl is a command-line client for the Gardener which configures access to clusters and cloud provider CLI tools. Wh... |
| CVE-2025-14044 | HIGH | 8.1 | 0.5% | Dec 12, 2025 | The Visitor Logic Lite plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, ... |
| CVE-2025-13334 | HIGH | 8.1 | 0.2% | Dec 12, 2025 | The Blaze Demo Importer plugin for WordPress is vulnerable to unauthorized database resets and file deletion due to a mi... |
| CVE-2025-12968 | HIGH | 8.8 | 0.5% | Dec 12, 2025 | The Infility Global plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and... |
| CVE-2025-12824 | HIGH | 8.8 | 0.7% | Dec 12, 2025 | The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ... |
| CVE-2025-13886 | HIGH | 7.5 | 0.5% | Dec 12, 2025 | The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ... |
| CVE-2025-10451 | HIGH | 8.2 | 0.1% | Dec 12, 2025 | Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption. |
| CVE-2025-67779 | HIGH | 7.5 | 18.9% | Dec 12, 2025 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den... |
| CVE-2025-66446 | HIGH | 7.5 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow... |
| CVE-2025-34506 | HIGH | 8.8 | 0.8% | Dec 11, 2025 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator... |
| CVE-2025-66586 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exp... |
| CVE-2025-66585 | HIGH | 7.8 | 0.2% | Dec 11, 2025 | In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corrup... |
| CVE-2025-66429 | HIGH | 8.8 | 0.7% | Dec 11, 2025 | An issue was discovered in cPanel 110 through 132. A directory traversal vulnerability within the Team Manager API allow... |
| CVE-2025-55184 | HIGH | 7.5 | 65.6% | Dec 11, 2025 | A pre-authentication denial of service vulnerability exists in React Server Components versions 19.0.0, 19.0.1 19.1.0, 1... |
| CVE-2025-36936 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to an integer overflow. Thi... |
| CVE-2025-36935 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In trusty_ffa_mem_reclaim of shared-mem-smcall.c, there is a possible memory corruption due to uninitialized data. This ... |
| CVE-2025-36934 | HIGH | 7.4 | 0.1% | Dec 11, 2025 | In bigo_worker_thread of private/google-modules/video/gchips/bigo.c, there is a possible use after free due to a race co... |
| CVE-2025-36932 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In tracepoint_msg_handler of cpm/google/lib/tracepoint/tracepoint_ipc.c, there is a possible memory overwrite due to imp... |
| CVE-2025-36931 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea... |
| CVE-2025-36930 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to a missing bounds check. This could lea... |
| CVE-2025-36928 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetHostAddress of gxp_buffer.h, there is a possible out of bounds write due to an incorrect bounds check. This could ... |
| CVE-2025-36927 | HIGH | 7.8 | 0.1% | Dec 11, 2025 | In GetTachyonCommand of tachyon_server_common.h, there is a possible out of bounds write due to a missing bounds check. ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now