2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13489 | MEDIUM | 5.9 | 0.2% | Dec 15, 2025 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.3 IBM DevOps Deploy transmits data in clear text that could allow an attac... |
| CVE-2025-12035 | MEDIUM | 6.5 | 0.2% | Dec 15, 2025 | An integer overflow condition exists in Bluetooth Host stack, within the bt_br_acl_recv routine a critical path for proc... |
| CVE-2025-65835 | MEDIUM | 6.2 | 0.2% | Dec 15, 2025 | The Cordova plugin cordova-plugin-x-socialsharing (SocialSharing-PhoneGap-Plugin) for Android 6.0.4, registers an export... |
| CVE-2025-51962 | MEDIUM | 6.1 | 0.2% | Dec 15, 2025 | A HTML Injection vulnerability in the comment section of the project page in MicroStudio 24.01.29 allows remote attacker... |
| CVE-2025-66436 | MEDIUM | 4.3 | 0.3% | Dec 15, 2025 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_terms_and_conditions method of Frappe ERPNext t... |
| CVE-2025-66435 | MEDIUM | 4.3 | 0.3% | Dec 15, 2025 | An SSTI (Server-Side Template Injection) vulnerability exists in the get_contract_template method of Frappe ERPNext thro... |
| CVE-2025-55901 | MEDIUM | 6.5 | 1.1% | Dec 15, 2025 | TOTOLINK A3300R V17.0.0cu.596_B20250515 is vulnerable to command injection in the function NTPSyncWithHost via the host_... |
| CVE-2025-55893 | MEDIUM | 6.5 | 1.1% | Dec 15, 2025 | TOTOLINK N200RE V9.3.5u.6437_B20230519 is vulnerable to command Injection in setOpModeCfg via hostName. |
| CVE-2025-66963 | MEDIUM | 5.5 | 0.1% | Dec 15, 2025 | An issue in Hitron HI3120 v.7.2.4.5.2b1 allows a local attacker to obtain sensitive information via the Logout option in... |
| CVE-2025-66843 | MEDIUM | 5.4 | 0.1% | Dec 15, 2025 | grav before v1.7.49.5 has a Stored Cross-Site Scripting (Stored XSS) vulnerability in the page editing functionality. An... |
| CVE-2025-14387 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions ... |
| CVE-2025-14003 | MEDIUM | 4.3 | 0.2% | Dec 15, 2025 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-13950 | MEDIUM | 5.3 | 0.3% | Dec 15, 2025 | The OneSignal – Web Push Notifications plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2025-13728 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The FluentAuth – The Ultimate Authorization & Security Plugin for WordPress plugin for WordPress is vulnerable to Stored... |
| CVE-2025-13610 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vu... |
| CVE-2025-13608 | MEDIUM | 6.4 | 0.2% | Dec 15, 2025 | The CC Child Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'child_pages' shortcode in ... |
| CVE-2025-13367 | MEDIUM | 6.4 | 0.3% | Dec 15, 2025 | The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restrict... |
| CVE-2025-12900 | MEDIUM | 4.3 | 0.2% | Dec 15, 2025 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorizatio... |
| CVE-2025-65782 | MEDIUM | 6.5 | 0.2% | Dec 15, 2025 | An issue was discovered in Wekan The Open Source kanban board system up to version 18.15, fixed in 18.16. Authorization ... |
| CVE-2025-65431 | MEDIUM | 5.4 | 0.1% | Dec 15, 2025 | An issue was discovered in allauth-django before 65.13.0. Both Okta and NetIQ were using preferred_username as the ident... |
| CVE-2025-65430 | MEDIUM | 5.4 | 0.1% | Dec 15, 2025 | An issue was discovered in allauth-django before 65.13.0. IdP: marking a user as is_active=False after having handed tok... |
| CVE-2025-66388 | MEDIUM | 6.5 | 0.4% | Dec 15, 2025 | A vulnerability in Apache Airflow allowed authenticated UI users to view secret values in rendered templates due to secr... |
| CVE-2025-37732 | MEDIUM | 5.4 | 0.2% | Dec 15, 2025 | Improper neutralization of input during web page generation ('Cross-site Scripting') (CWE-79) allows an authenticated us... |
| CVE-2025-14714 | MEDIUM | 6.5 | 0.1% | Dec 15, 2025 | An Authentication Bypass vulnerability existed where the application bundled an interpreter (Python) that inherits the T... |
| CVE-2025-11670 | MEDIUM | 4.3 | 0.4% | Dec 15, 2025 | Zohocorp ManageEngine ADManager Plus versions before 8025 are vulnerable to NTLM Hash Exposure. This vulnerability is e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now