2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12650 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter... |
| CVE-2025-13839 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' s... |
| CVE-2025-13670 | MEDIUM | 6.7 | 0.1% | Dec 12, 2025 | The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability |
| CVE-2025-13669 | MEDIUM | 6.7 | 0.1% | Dec 12, 2025 | Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hi... |
| CVE-2025-13665 | MEDIUM | 6.7 | 0.1% | Dec 12, 2025 | The System Console Utility for Windows is vulnerable to a DLL planting vulnerability |
| CVE-2025-13052 | MEDIUM | 5.9 | 0.2% | Dec 12, 2025 | When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL c... |
| CVE-2025-67780 | MEDIUM | 4.2 | 0.1% | Dec 11, 2025 | SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un... |
| CVE-2025-66452 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing... |
| CVE-2025-66451 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests... |
| CVE-2025-66450 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic... |
| CVE-2025-34504 | MEDIUM | 6.1 | 0.3% | Dec 11, 2025 | KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ... |
| CVE-2025-34499 | MEDIUM | 6.9 | 0.4% | Dec 11, 2025 | AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to poten... |
| CVE-2025-13668 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Pro Edition Design Software may allow escalation of privilege. |
| CVE-2025-64702 | MEDIUM | 5.3 | 0.3% | Dec 11, 2025 | quic-go is an implementation of the QUIC protocol in Go. Versions 0.56.0 and below are vulnerable to excessive memory al... |
| CVE-2025-55816 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | HotelDruid v3.0.7 and before is vulnerable to Cross Site Scripting (XSS) in the /modifica_app.php file. |
| CVE-2025-14293 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | The WP Job Portal plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 2.4.0 ... |
| CVE-2025-13664 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | A potential security vulnerability in Quartus® Prime Standard Edition Design Software may allow escalation of privilege. |
| CVE-2025-13663 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | Under certain circumstances, the Quartus Prime Pro Installer for Windows does not check the permissions of the Quartus t... |
| CVE-2025-55183 | MEDIUM | 5.3 | 62.4% | Dec 11, 2025 | An information leak vulnerability exists in specific configurations of React Server Components versions 19.0.0, 19.0.1 1... |
| CVE-2025-36938 | MEDIUM | 6.8 | 0.1% | Dec 11, 2025 | In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead t... |
| CVE-2025-36929 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In AreFencesRegistered of gxp_fence_manager.cc, there is a possible information leak due to improper input validation. T... |
| CVE-2025-36922 | MEDIUM | 6.7 | 0.1% | Dec 11, 2025 | In bigo_map of bigo_iommu.c, there is a possible information disclosure due to a use after free. This could lead to loc... |
| CVE-2025-36921 | MEDIUM | 5.5 | 0.1% | Dec 11, 2025 | In ProtocolPsUnthrottleApn() of protocolpsadapter.cpp, there is a possible out of bounds read due to a missing bounds ch... |
| CVE-2025-36917 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | In SwDcpItg of up_L2commonPdcpSecurity.cpp, there is a possible denial of service due to an incorrect bounds check. This... |
| CVE-2025-36912 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | In cellular modem, there is a possible denial of service due to a logic error in the code. This could lead to remote den... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now