2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11759 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-62223 | MEDIUM | 4.3 | 0.4% | Dec 5, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ... |
| CVE-2025-14052 | MEDIUM | 6.5 | 0.2% | Dec 5, 2025 | A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function get... |
| CVE-2025-66563 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user in... |
| CVE-2025-66561 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting ... |
| CVE-2025-6946 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi... |
| CVE-2025-65900 | MEDIUM | 6.5 | 0.3% | Dec 4, 2025 | Kalmia CMS version 0.2.0 contains an Incorrect Access Control vulnerability in the /kal-api/auth/users API endpoint. Due... |
| CVE-2025-65899 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | Kalmia CMS version 0.2.0 contains a user enumeration vulnerability in its authentication mechanism. The application retu... |
| CVE-2025-1910 | MEDIUM | 6.3 | 0.2% | Dec 4, 2025 | The WatchGuard Mobile VPN with SSL Client on Windows allows a locally authenticated non-administrative Windows user to e... |
| CVE-2025-13940 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | An Expected Behavior Violation [CWE-440] vulnerability in WatchGuard Fireware OS may allow an attacker to bypass the Fir... |
| CVE-2025-13939 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13938 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13937 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-13936 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard ... |
| CVE-2025-12986 | MEDIUM | 6 | 0.2% | Dec 4, 2025 | When a WF200/WGM160P device is configured to operate as an Access Point, it may be vulnerable to a denial of service tri... |
| CVE-2025-66574 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | TranzAxis 3.2.41.10.26 allows authenticated users to inject cross-site scripting via the `Open Object in Tree` endpoint,... |
| CVE-2025-66572 | MEDIUM | 6.9 | 0.4% | Dec 4, 2025 | Loaded Commerce 6.6 contains a client-side template injection vulnerability via the search parameter that allows unauthe... |
| CVE-2025-65959 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.37, a St... |
| CVE-2025-65806 | MEDIUM | 4.3 | 0.3% | Dec 4, 2025 | The E-POINT CMS eagle.gsam-1169.1 file upload feature improperly handles nested archive files. An attacker can upload a ... |
| CVE-2025-63499 | MEDIUM | 6.1 | 0.3% | Dec 4, 2025 | Alinto Sogo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the theme parameter. |
| CVE-2025-12996 | MEDIUM | 4.1 | 0.1% | Dec 4, 2025 | Medtronic CareLink Network allows a local attacker with access to log files on an internal API server to view plaintext ... |
| CVE-2025-12994 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | Medtronic CareLink Network allows an unauthenticated remote attacker to initiate a request for security questions to an ... |
| CVE-2025-63361 | MEDIUM | 5.7 | 0.3% | Dec 4, 2025 | Waveshare RS232/485 TO WIFI ETH (B) Serial to Ethernet/Wi-Fi Gateway Firmware V3.1.1.0: HW 4.3.2.1: Webpage V7.04T.07.00... |
| CVE-2025-59788 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | Cross-site scripting (XSS) vulnerability in a reachable files_pdfviewer example directory in Nextcloud with versions bef... |
| CVE-2025-14013 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | A vulnerability was identified in JIZHICMS up to 2.5.5. The impacted element is an unknown function of the file /index.p... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now