2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13145 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2025-12646 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u... |
| CVE-2025-12426 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-12852 | HIGH | 8.4 | 0.1% | Nov 19, 2025 | DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC ... |
| CVE-2025-65015 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2025-64324 | HIGH | 7.7 | 0.2% | Nov 18, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos... |
| CVE-2025-62406 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset ... |
| CVE-2025-63215 | HIGH | 7.2 | 0.4% | Nov 18, 2025 | The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u... |
| CVE-2025-63227 | HIGH | 7.2 | 0.5% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne... |
| CVE-2025-37162 | HIGH | 8.8 | 0.8% | Nov 18, 2025 | A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduc... |
| CVE-2025-37161 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke... |
| CVE-2025-63955 | HIGH | 7.5 | 0.2% | Nov 18, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst... |
| CVE-2025-61662 | HIGH | 7.8 | 0.2% | Nov 18, 2025 | A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh... |
| CVE-2025-60455 | HIGH | 8.4 | 0.3% | Nov 18, 2025 | Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca... |
| CVE-2025-37163 | HIGH | 7.2 | 0.9% | Nov 18, 2025 | A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave ... |
| CVE-2025-37159 | HIGH | 7.3 | 0.2% | Nov 18, 2025 | A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticate... |
| CVE-2025-37158 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti... |
| CVE-2025-37157 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenti... |
| CVE-2025-37155 | HIGH | 7.8 | 0.1% | Nov 18, 2025 | A vulnerability in the SSH restricted shell interface of the network management services allows improper access control ... |
| CVE-2025-64076 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | Multiple vulnerabilities exist in cbor2 through version 5.7.0 in the decode_definite_long_string() function of the C ext... |
| CVE-2025-63829 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | eProsima Fast-DDS v3.3 and before has an infinite loop vulnerability caused by integer overflow in the Time_t:: fraction... |
| CVE-2025-58692 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerabi... |
| CVE-2025-58413 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiO... |
| CVE-2025-58034 | HIGH | 7.2 | 54.4% | Nov 18, 2025 | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vul... |
| CVE-2025-56527 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now