2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13536 | HIGH | 8.8 | 0.5% | Nov 27, 2025 | The Blubrry PowerPress plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida... |
| CVE-2025-7820 | HIGH | 7.5 | 0.3% | Nov 27, 2025 | The SKT PayPal for WooCommerce plugin for WordPress is vulnerable to Payment Bypass in all versions up to, and including... |
| CVE-2025-13680 | HIGH | 8.8 | 0.2% | Nov 27, 2025 | The Tiger theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 101.2.1. This ... |
| CVE-2025-12758 | HIGH | 7.7 | 0.5% | Nov 27, 2025 | Versions of the package validator before 13.15.22 are vulnerable to Incomplete Filtering of One or More Instances of Spe... |
| CVE-2025-66314 | HIGH | 7.5 | 0.2% | Nov 27, 2025 | Improper Privilege Management vulnerability in ZTE ElasticNet UME R32 on Linux allows Accessing Functionality Not Proper... |
| CVE-2025-0658 | HIGH | 8.7 | 0.3% | Nov 27, 2025 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev... |
| CVE-2025-0657 | HIGH | 8.8 | 0.3% | Nov 27, 2025 | A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed... |
| CVE-2025-66035 | HIGH | 7.7 | 0.6% | Nov 26, 2025 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2025-66031 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R... |
| CVE-2025-64344 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64335 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64334 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64333 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64332 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64331 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64330 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-62593 | HIGH | 8.8 | 62.5% | Nov 26, 2025 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited... |
| CVE-2025-65202 | HIGH | 8 | 7.2% | Nov 26, 2025 | TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, explo... |
| CVE-2025-65278 | HIGH | 7.5 | 0.2% | Nov 26, 2025 | An issue was discovered in file users.json in GroceryMart commit 21934e6 (2020-10-23) allowing unauthenticated attackers... |
| CVE-2025-12571 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.4.5, 18.5 before 18.5.3, and ... |
| CVE-2025-66028 | HIGH | 8.2 | 0.3% | Nov 26, 2025 | OneUptime is a solution for monitoring and managing online services. Prior to version 8.0.5567, OneUptime is vulnerable ... |
| CVE-2025-65966 | HIGH | 8.1 | 0.3% | Nov 26, 2025 | OneUptime is a solution for monitoring and managing online services. In version 9.0.5598, a low-permission user can crea... |
| CVE-2025-65672 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows unauthorized share and invite access to course sett... |
| CVE-2025-64129 | HIGH | 7.6 | 0.4% | Nov 26, 2025 | Zenitel TCIV-3+ is vulnerable to an out-of-bounds write vulnerability, which could allow a remote attacker to crash the... |
| CVE-2025-55471 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Incorrect access control in the getUserFormData function of youlai-boot v2.21.1 allows attackers to access sensitive inf... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now