2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13551 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an un... |
| CVE-2025-13550 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown functi... |
| CVE-2025-13549 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability was found in D-Link DIR-822K 1.00. This issue affects the function sub_455524 of the file /boafrm/formNt... |
| CVE-2025-13548 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects un... |
| CVE-2025-13547 | HIGH | 8.8 | 0.7% | Nov 23, 2025 | A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the fi... |
| CVE-2025-13545 | HIGH | 7.2 | 0.3% | Nov 23, 2025 | A security vulnerability has been detected in ashraf-kabir travel-agency up to 1f25aa03544bc5fb7a9e846f8a7879cecdb0cad3.... |
| CVE-2025-13526 | HIGH | 7.5 | 0.3% | Nov 22, 2025 | The OneClick Chat to Order plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to,... |
| CVE-2025-13384 | HIGH | 7.5 | 0.3% | Nov 22, 2025 | The CP Contact Form with PayPal plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and i... |
| CVE-2025-65947 | HIGH | 8.7 | 0.3% | Nov 21, 2025 | thread-amount is a tool that gets the amount of threads in the current process. Prior to version 0.2.2, there are resour... |
| CVE-2025-65946 | HIGH | 8.1 | 0.6% | Nov 21, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Prior to version 3.26.7, Due to an error... |
| CVE-2025-12888 | HIGH | 7.5 | 0.3% | Nov 21, 2025 | Vulnerability in X25519 constant-time cryptographic implementations due to timing side channels introduced by compiler o... |
| CVE-2025-11931 | HIGH | 8.2 | 0.3% | Nov 21, 2025 | Integer Underflow Leads to Out-of-Bounds Access in XChaCha20-Poly1305 Decrypt. This issue is hit specifically with a cal... |
| CVE-2025-65109 | HIGH | 8.5 | 0.2% | Nov 21, 2025 | Minder is an open source software supply chain security platform. In Minder Helm version 0.20241106.3386+ref.2507dbf and... |
| CVE-2025-65106 | HIGH | 8.3 | 0.5% | Nov 21, 2025 | LangChain is a framework for building agents and LLM-powered applications. From versions 0.3.79 and prior and 1.0.0 to 1... |
| CVE-2025-65102 | HIGH | 8.7 | 0.3% | Nov 21, 2025 | PJSIP is a free and open source multimedia communication library. Prior to version 2.16, Opus PLC may zero-fill the inpu... |
| CVE-2025-11935 | HIGH | 7.5 | 0.2% | Nov 21, 2025 | With TLS 1.3 pre-shared key (PSK) a malicious or faulty server could ignore the request for PFS (perfect forward secrecy... |
| CVE-2025-11087 | HIGH | 8.8 | 0.2% | Nov 21, 2025 | The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up ... |
| CVE-2025-62626 | HIGH | 7.2 | 0.2% | Nov 21, 2025 | Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned ... |
| CVE-2025-62609 | HIGH | 7.5 | 0.3% | Nov 21, 2025 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault ... |
| CVE-2025-13132 | HIGH | 7.4 | 0.2% | Nov 21, 2025 | This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) ap... |
| CVE-2025-13470 | HIGH | 7.7 | 0.3% | Nov 21, 2025 | In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session K... |
| CVE-2025-12973 | HIGH | 7.2 | 0.9% | Nov 21, 2025 | The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra... |
| CVE-2025-66095 | HIGH | 8.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi... |
| CVE-2025-66073 | HIGH | 7.2 | 0.4% | Nov 21, 2025 | Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue... |
| CVE-2025-66055 | HIGH | 7.2 | 0.4% | Nov 21, 2025 | Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Obje... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now