2025 CVE Vulnerabilities
45,324 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-66550 | MEDIUM | 5.7 | 0.3% | Dec 5, 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar ... |
| CVE-2025-66547 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 31.0.1, non-... |
| CVE-2025-66512 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Server Enterprise prior to 31.0.12 and ... |
| CVE-2025-66511 | MEDIUM | 6.5 | 0.2% | Dec 5, 2025 | Nextcloud Calendar is a calendar app for Nextcloud. Prior to 6.0.3, the Calendar app generates participant tokens for me... |
| CVE-2025-66510 | MEDIUM | 4.9 | 0.3% | Dec 5, 2025 | Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud E... |
| CVE-2025-14104 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | A flaw was found in util-linux. This vulnerability allows a heap buffer overread when processing 256-byte usernames, spe... |
| CVE-2025-64056 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | File upload vulnerability in Fanvil x210 V2 2.12.20 allows unauthenticated attackers on the local network to store arbit... |
| CVE-2025-64052 | MEDIUM | 5.1 | 2.9% | Dec 5, 2025 | An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to execute arb... |
| CVE-2025-14089 | MEDIUM | 6.3 | 0.2% | Dec 5, 2025 | A vulnerability was identified in Himool ERP up to 2.2. Affected by this issue is the function update_account of the fil... |
| CVE-2025-14088 | MEDIUM | 6.3 | 0.2% | Dec 5, 2025 | A vulnerability was determined in ketr JEPaaS up to 7.2.8. Affected by this vulnerability is an unknown functionality of... |
| CVE-2025-6966 | MEDIUM | 5.5 | 0.1% | Dec 5, 2025 | NULL pointer dereference in TagSection.keys() in python-apt on APT-based Linux systems allows a local attacker to cause ... |
| CVE-2025-66200 | MEDIUM | 5.4 | 0.6% | Dec 5, 2025 | mod_userdir+suexec bypass via AllowOverride FileInfo vulnerability in Apache HTTP Server. Users with access to use the R... |
| CVE-2025-65082 | MEDIUM | 6.5 | 0.8% | Dec 5, 2025 | Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache HTTP Server through environment va... |
| CVE-2025-13620 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Wp Social Login and Register Social Counter plugin for WordPress is vulnerable to missing authorization in versions ... |
| CVE-2025-13739 | MEDIUM | 6.4 | 0.3% | Dec 5, 2025 | The CryptX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `cryptx` shortcode in all ... |
| CVE-2025-13682 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The Trail Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions u... |
| CVE-2025-13678 | MEDIUM | 6.4 | 0.3% | Dec 5, 2025 | The Thai Lottery Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `thailottery` shortcod... |
| CVE-2025-12876 | MEDIUM | 5.3 | 0.3% | Dec 5, 2025 | The Projectopia – WordPress Project Management plugin for WordPress is vulnerable to unauthorized modification of data d... |
| CVE-2025-13684 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The ARK Related Posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 2.19. This is due to m... |
| CVE-2025-12130 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to... |
| CVE-2025-13515 | MEDIUM | 6.1 | 0.2% | Dec 5, 2025 | The Nouri.sh Newsletter plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF... |
| CVE-2025-12373 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Torod – The smart shipping and delivery portal for e-shops and retailers plugin for WordPress is vulnerable to Cross... |
| CVE-2025-12355 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The Payaza plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on ... |
| CVE-2025-12354 | MEDIUM | 4.3 | 0.2% | Dec 5, 2025 | The Live CSS Preview plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-12186 | MEDIUM | 4.4 | 0.2% | Dec 5, 2025 | The Weekly Planner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now