2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11087 | HIGH | 8.8 | 0.2% | Nov 21, 2025 | The Zegen Core plugin for WordPress is vulnerable to Cross-Site Request Forgery to Arbitrary File Upload in versions up ... |
| CVE-2025-62626 | HIGH | 7.2 | 0.2% | Nov 21, 2025 | Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned ... |
| CVE-2025-62609 | HIGH | 7.5 | 0.3% | Nov 21, 2025 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a segmentation fault ... |
| CVE-2025-13132 | HIGH | 7.4 | 0.2% | Nov 21, 2025 | This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) ap... |
| CVE-2025-13470 | HIGH | 7.7 | 0.3% | Nov 21, 2025 | In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session K... |
| CVE-2025-12973 | HIGH | 7.2 | 0.9% | Nov 21, 2025 | The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra... |
| CVE-2025-66095 | HIGH | 8.5 | 0.2% | Nov 21, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design Kivi... |
| CVE-2025-66073 | HIGH | 7.2 | 0.4% | Nov 21, 2025 | Deserialization of Untrusted Data vulnerability in Cozmoslabs WP Webhooks wp-webhooks allows Object Injection.This issue... |
| CVE-2025-66055 | HIGH | 7.2 | 0.4% | Nov 21, 2025 | Deserialization of Untrusted Data vulnerability in Icegram Email Subscribers & Newsletters email-subscribers allows Obje... |
| CVE-2025-40210 | HIGH | 7.5 | 0.2% | Nov 21, 2025 | In the Linux kernel, the following vulnerability has been resolved: Revert "NFSD: Remove the cap on number of operation... |
| CVE-2025-13138 | HIGH | 7.5 | 1.5% | Nov 21, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'columns_search' parameter of the selec... |
| CVE-2025-12160 | HIGH | 7.2 | 0.2% | Nov 21, 2025 | The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' p... |
| CVE-2025-13156 | HIGH | 8.8 | 0.6% | Nov 21, 2025 | The Vitepos – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to mi... |
| CVE-2025-13322 | HIGH | 8.1 | 0.5% | Nov 21, 2025 | The WP AUDIO GALLERY plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2025-13159 | HIGH | 7.1 | 0.3% | Nov 21, 2025 | The Flo Forms – Easy Drag & Drop Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG ... |
| CVE-2025-12138 | HIGH | 8.8 | 0.6% | Nov 21, 2025 | The URL Image Importer plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type valida... |
| CVE-2025-12135 | HIGH | 7.2 | 0.3% | Nov 21, 2025 | The WPBookit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css_code' parameter in all versi... |
| CVE-2025-11985 | HIGH | 8.8 | 0.3% | Nov 21, 2025 | The Realty Portal plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege esc... |
| CVE-2025-64695 | HIGH | 8.4 | 0.1% | Nov 21, 2025 | Uncontrolled search path element issue exists in the installer of LogStare Collector (for Windows). If exploited, arbitr... |
| CVE-2025-58097 | HIGH | 7.8 | 0.1% | Nov 21, 2025 | The installation directory of LogStare Collector is configured with incorrect access permissions. A non-administrative u... |
| CVE-2025-64751 | HIGH | 8.8 | 0.3% | Nov 21, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
| CVE-2025-62164 | HIGH | 8.8 | 0.8% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From versions 0.10.2 to before 0.11.1, a memor... |
| CVE-2025-64660 | HIGH | 8 | 0.5% | Nov 20, 2025 | Improper access control in GitHub Copilot and Visual Studio Code allows an authorized attacker to execute code over a ne... |
| CVE-2025-36072 | HIGH | 8.8 | 0.4% | Nov 20, 2025 | IBM webMethods Integration 10.11 through 10.11_Core_Fix22, 10.15 through 10.15_Core_Fix22, and 11.1 through 11.1_Core_Fi... |
| CVE-2025-61138 | HIGH | 7.5 | 0.3% | Nov 20, 2025 | Qlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now