2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10702 | HIGH | 8.6 | 0.3% | Nov 19, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Progress DataDirect Connect for JDBC drivers,... |
| CVE-2025-63219 | HIGH | 7.5 | 0.4% | Nov 19, 2025 | The ITEL ISO FM SFN Adapter (firmware ISO2 2.0.0.0, WebServer 2.0) is vulnerable to session hijacking due to improper se... |
| CVE-2025-13395 | HIGH | 7.3 | 0.3% | Nov 19, 2025 | A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted el... |
| CVE-2025-12472 | HIGH | 7.1 | 0.2% | Nov 19, 2025 | An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git direct... |
| CVE-2025-11230 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially ... |
| CVE-2025-13035 | HIGH | 8 | 0.3% | Nov 19, 2025 | The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. ... |
| CVE-2025-12484 | HIGH | 7.2 | 0.3% | Nov 19, 2025 | The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for... |
| CVE-2025-12056 | HIGH | 8.3 | 0.2% | Nov 19, 2025 | Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers. |
| CVE-2025-11243 | HIGH | 8.3 | 0.4% | Nov 19, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo... |
| CVE-2025-13145 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2025-12646 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u... |
| CVE-2025-12426 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-12852 | HIGH | 8.4 | 0.1% | Nov 19, 2025 | DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC ... |
| CVE-2025-65015 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2025-64324 | HIGH | 7.7 | 0.2% | Nov 18, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. The `hostDisk` feature in KubeVirt allows mounting a hos... |
| CVE-2025-62406 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | Piwigo is a full featured open source photo gallery application for the web. In Piwigo 15.6.0, using the password reset ... |
| CVE-2025-63215 | HIGH | 7.2 | 0.4% | Nov 18, 2025 | The Sound4 IMPACT web-based management interface is vulnerable to Remote Code Execution (RCE) via a malicious firmware u... |
| CVE-2025-63227 | HIGH | 7.2 | 0.5% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains an unrestricted file upload vulne... |
| CVE-2025-37162 | HIGH | 8.8 | 0.8% | Nov 18, 2025 | A vulnerability in the command line interface of affected devices could allow an authenticated remote attacker to conduc... |
| CVE-2025-37161 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | A vulnerability in the web-based management interface of affected products could allow an unauthenticated remote attacke... |
| CVE-2025-63955 | HIGH | 7.5 | 0.2% | Nov 18, 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in the manage-students.php component of PHPGurukul Student Record Syst... |
| CVE-2025-61662 | HIGH | 7.8 | 0.2% | Nov 18, 2025 | A Use-After-Free vulnerability has been discovered in GRUB's gettext module. This flaw stems from a programming error wh... |
| CVE-2025-60455 | HIGH | 8.4 | 0.3% | Nov 18, 2025 | Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvca... |
| CVE-2025-37163 | HIGH | 7.2 | 0.9% | Nov 18, 2025 | A command injection vulnerability has been identified in the command line interface of the HPE Aruba Networking Airwave ... |
| CVE-2025-37159 | HIGH | 7.3 | 0.2% | Nov 18, 2025 | A vulnerability in the web management interface of the AOS-CX OS user authentication service could allow an authenticate... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now