2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13633 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromi... |
| CVE-2025-13631 | HIGH | 8.8 | 0.3% | Dec 2, 2025 | Inappropriate implementation in Google Updater in Google Chrome on Mac prior to 143.0.7499.41 allowed a remote attacker ... |
| CVE-2025-13630 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Type Confusion in V8 in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-66399 | HIGH | 8.8 | 10.8% | Dec 2, 2025 | Cacti is an open source performance and fault management framework. Prior to 1.2.29, there is an input-validation flaw i... |
| CVE-2025-65844 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | EverShop 2.0.1 allows a remote unauthenticated attacker to upload arbitrary files and create directories via the /api/im... |
| CVE-2025-13827 | HIGH | 8.8 | 0.4% | Dec 2, 2025 | Summary Arbitrary files can be uploaded via the GrapesJS Builder, as the types of files that can be uploaded are not res... |
| CVE-2025-64460 | HIGH | 7.5 | 2.1% | Dec 2, 2025 | An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django... |
| CVE-2025-59702 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59697 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-13876 | HIGH | 7.8 | 0.3% | Dec 2, 2025 | A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is ... |
| CVE-2025-41015 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ... |
| CVE-2025-41014 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | User Enumeration Vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attacker ... |
| CVE-2025-13295 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message ... |
| CVE-2025-12465 | HIGH | 8.6 | 0.2% | Dec 2, 2025 | A Blind SQL injection vulnerability has been identified in QuickCMS. Improper neutralization of input provided by a high... |
| CVE-2025-11789 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | Out-of-bounds read vulnerability in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The 'DownloadFile' function converts a parame... |
| CVE-2025-11787 | HIGH | 8.8 | 1.0% | Dec 2, 2025 | Command injection vulnerability in the operating system in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2 through the 'GetDNS()',... |
| CVE-2025-11781 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | Use of hardcoded cryptographic keys in Circutor SGE-PLC1000/SGE-PLC50 v9.0.2. The affected firmware contains a hardcoded... |
| CVE-2025-13871 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | Cross-Site Request Forgery (CSRF) in the resource-management feature of ObjectPlanet Opinio 7.26 rev12562 allows to ... |
| CVE-2025-13724 | HIGH | 7.5 | 0.3% | Dec 2, 2025 | The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to time-based blind SQL Injection via the... |
| CVE-2025-13534 | HIGH | 8.8 | 0.2% | Dec 2, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in al... |
| CVE-2025-13516 | HIGH | 8.1 | 0.9% | Dec 2, 2025 | The SureMail – SMTP and Email Logs Plugin for WordPress is vulnerable to Unrestricted Upload of File with Dangerous Type... |
| CVE-2025-10971 | HIGH | 8.8 | 0.1% | Dec 2, 2025 | Insecure Storage of Sensitive Information vulnerability in MeetMe on iOS, Android allows Retrieve Embedded Sensitive Dat... |
| CVE-2025-13000 | HIGH | 7.7 | 0.3% | Dec 2, 2025 | The db-access WordPress plugin through 0.8.7 does not have authorization in an AJAX action, allowing any authenticated u... |
| CVE-2025-13387 | HIGH | 7.2 | 0.3% | Dec 2, 2025 | The Kadence WooCommerce Email Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custome... |
| CVE-2025-20768 | HIGH | 7.8 | 0.1% | Dec 2, 2025 | In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now