2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-40210 | HIGH | 7.5 | 0.2% | Nov 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operation... |
| CVE-2025-13138 | HIGH | 7.5 | 1.4% | Nov 21, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec... |
| CVE-2025-12160 | HIGH | 7.2 | 0.2% | Nov 21, 2025 | The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p... |
| CVE-2025-13156 | HIGH | 8.8 | 0.6% | Nov 21, 2025 | The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi... |
| CVE-2025-13322 | HIGH | 8.1 | 0.5% | Nov 21, 2025 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2025-13159 | HIGH | 7.1 | 0.3% | Nov 21, 2025 | The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG ... |
| CVE-2025-12138 | HIGH | 8.8 | 0.6% | Nov 21, 2025 | The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida... |
| CVE-2025-12135 | HIGH | 7.2 | 0.3% | Nov 21, 2025 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi... |
| CVE-2025-11985 | HIGH | 8.8 | 0.3% | Nov 21, 2025 | The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc... |
| CVE-2025-64695 | HIGH | 8.4 | 0.1% | Nov 21, 2025 | Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitr... |
| CVE-2025-58097 | HIGH | 7.8 | 0.1% | Nov 21, 2025 | The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u... |
| CVE-2025-64751 | HIGH | 8.8 | 0.3% | Nov 21, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2025-62164 | HIGH | 8.8 | 0.8% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor... |
| CVE-2025-64660 | HIGH | 8 | 0.5% | Nov 20, 2025 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne... |
| CVE-2025-36072 | HIGH | 8.8 | 0.4% | Nov 20, 2025 | IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi... |
| CVE-2025-61138 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory. |
| CVE-2025-36160 | HIGH | 7.5 | 0.2% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could disclose sensitive server information from HTTP response headers that could aid in... |
| CVE-2025-13087 | HIGH | 7.5 | 6.3% | Nov 20, 2025 | A vulnerability exists in the Opto22 Groov Manage REST API on GRV-EPIC and groov RIO Products that allows remote code ex... |
| CVE-2025-64770 | HIGH | 7 | 0.2% | Nov 20, 2025 | The affected products allow unauthenticated access to Open Network Video Interface Forum (ONVIF) services, which may all... |
| CVE-2025-62674 | HIGH | 7 | 0.2% | Nov 20, 2025 | The affected product allows unauthenticated access to Real Time Streaming Protocol (RTSP) services, which may allow an a... |
| CVE-2025-25613 | HIGH | 7.5 | 0.2% | Nov 20, 2025 | FS Inc S3150-8T2F 8-Port Gigabit Ethernet L2+ Switch, 8 x Gigabit RJ45, with 2 x 1Gb SFP, Fanless. All versions before 2... |
| CVE-2025-48986 | HIGH | 8.8 | 0.6% | Nov 20, 2025 | Authorization bypass in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes an logged in attacker to change othe... |
| CVE-2025-63889 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | The fetch function in file thinkphp\library\think\Template.php in ThinkPHP 5.0.24 allows attackers to read arbitrary fil... |
| CVE-2025-62709 | HIGH | 8.8 | 0.3% | Nov 20, 2025 | ClipBucket v5 is an open source video sharing platform. In ClipBucket version 5.5.2, a change to network.class.php cause... |
| CVE-2025-12121 | HIGH | 7.3 | 0.3% | Nov 20, 2025 | Lite XL versions 2.1.8 and prior contain a vulnerability in the system.exec function, which allowed arbitrary command ex... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now