2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59697 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker... |
| CVE-2025-13876 | HIGH | 7.8 | 0.3% | Dec 2, 2025 | A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is ... |
| CVE-2025-41015 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ... |
| CVE-2025-41014 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ... |
| CVE-2025-13295 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message ... |
| CVE-2025-12465 | HIGH | 8.6 | 0.2% | Dec 2, 2025 | A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high... |
| CVE-2025-11789 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parame... |
| CVE-2025-11787 | HIGH | 8.8 | 0.9% | Dec 2, 2025 | Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()',... |
| CVE-2025-11781 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded... |
| CVE-2025-13871 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to ... |
| CVE-2025-13724 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the... |
| CVE-2025-13534 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al... |
| CVE-2025-13516 | HIGH | 8.1 | 0.9% | Dec 2, 2025 | The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type... |
| CVE-2025-10971 | HIGH | 8.8 | 0.1% | Dec 2, 2025 | Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Dat... |
| CVE-2025-13000 | HIGH | 7.7 | 0.3% | Dec 2, 2025 | The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated u... |
| CVE-2025-13387 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome... |
| CVE-2025-20768 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of... |
| CVE-2025-20767 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | In display, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of p... |
| CVE-2025-20766 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | In display, there is a possible memory corruption due to improper input validation. This could lead to local escalation ... |
| CVE-2025-20764 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | In smi, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of pr... |
| CVE-2025-20763 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | In mmdvfs, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of... |
| CVE-2025-12529 | HIGH | 8.8 | 0.5% | Dec 2, 2025 | The Cost Calculator Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path ... |
| CVE-2025-58482 | HIGH | 7.3 | 0.1% | Dec 2, 2025 | Improper access control in MPLocalService of MotionPhoto prior to version 4.1.51 allows local attackers to start privile... |
| CVE-2025-58481 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | Improper access control in MPRemoteService of MotionPhoto prior to version 4.1.51 allows local attackers to start privil... |
| CVE-2025-58480 | HIGH | 7.5 | 0.2% | Dec 2, 2025 | Heap-based buffer overflow in libimagecodec.quram.so prior to SMR Dec-2025 Release 1 allows remote attackers to access o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now