2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14331 | MEDIUM | 6.5 | 0.2% | Dec 9, 2025 | Same-origin policy bypass in the Request Handling component. This vulnerability was fixed in Firefox 146, Firefox ESR 11... |
| CVE-2025-14311 | MEDIUM | 6.8 | 0.2% | Dec 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects ... |
| CVE-2025-14284 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit... |
| CVE-2025-13642 | MEDIUM | 5.4 | 0.4% | Dec 9, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2025-13070 | MEDIUM | 6.6 | 0.4% | Dec 9, 2025 | The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener... |
| CVE-2025-13031 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c... |
| CVE-2025-12558 | MEDIUM | 4.3 | 0.3% | Dec 9, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2025-10876 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2025-10573 | MEDIUM | 6.1 | 29.5% | Dec 9, 2025 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute ... |
| CVE-2025-66491 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in... |
| CVE-2025-66490 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests us... |
| CVE-2025-66470 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.inter... |
| CVE-2025-66469 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are vulnerable to Reflected XSS through its ui.add_css,... |
| CVE-2025-66202 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | Astro is a web framework. Versions 5.15.7 and below have a double URL encoding bypass which allows any unauthenticated a... |
| CVE-2025-65962 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm... |
| CVE-2025-64760 | MEDIUM | 4.3 | 0.1% | Dec 8, 2025 | Tuleap is a free and open source suite for management of software development and collaboration. Versions of Tuleap Comm... |
| CVE-2025-64499 | MEDIUM | 5.4 | 0.1% | Dec 8, 2025 | Tuleap is a free and open source suite for management of software development and collaboration. Tuleap Community Editon... |
| CVE-2025-64498 | MEDIUM | 4.3 | 0.1% | Dec 8, 2025 | Tuleap is an Open Source Suite for management of software development and collaboration. Tuleap Community Edition versio... |
| CVE-2025-64497 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | Tuleap is an Open Source Suite for management of software development and collaboration. Versions below 17.0.99.17624313... |
| CVE-2025-36140 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM watsonx.data 2.2 through 2.2.1 could allow an authenticated user to cause a denial of service through ingestion pods... |
| CVE-2025-64650 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.18 could disclose sensitive user credentials in log files. |
| CVE-2025-62408 | MEDIUM | 5.9 | 0.4% | Dec 8, 2025 | c-ares is an asynchronous resolver library. Versions 1.32.3 through 1.34.5 terminate a query after maximum attempts whe... |
| CVE-2025-36017 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive in... |
| CVE-2025-36015 | MEDIUM | 6.5 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated us... |
| CVE-2025-33111 | MEDIUM | 4.3 | 0.2% | Dec 8, 2025 | IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 is vulnerable to creation of te... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now