2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13345 | HIGH | 8.8 | 0.4% | Nov 18, 2025 | A security vulnerability has been detected in SourceCodester Train Station Ticketing System 1.0. Affected by this issue ... |
| CVE-2025-41737 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | Due to webserver misconfiguration an unauthenticated remote attacker is able to read the source of php modules. |
| CVE-2025-41736 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | A low privileged remote attacker can upload a new or overwrite an existing python script by using a path traversal of th... |
| CVE-2025-41735 | HIGH | 8.8 | 0.5% | Nov 18, 2025 | A low privileged remote attacker can upload any file to an arbitrary location due to missing file check resulting in rem... |
| CVE-2025-4212 | HIGH | 7.2 | 0.2% | Nov 18, 2025 | The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file upl... |
| CVE-2025-13069 | HIGH | 8.8 | 0.6% | Nov 18, 2025 | The Enable SVG, WebP, and ICO Upload plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, ... |
| CVE-2025-12955 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | The Live sales notification for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versions ... |
| CVE-2025-13088 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | The Category and Product Woocommerce Tabs plugin for WordPress is vulnerable to Local File Inclusion in all versions up ... |
| CVE-2025-12775 | HIGH | 8.8 | 0.5% | Nov 18, 2025 | The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc... |
| CVE-2025-12528 | HIGH | 8.1 | 0.6% | Nov 18, 2025 | The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1... |
| CVE-2025-12411 | HIGH | 7.1 | 0.2% | Nov 18, 2025 | The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet... |
| CVE-2025-11620 | HIGH | 7.2 | 0.3% | Nov 18, 2025 | The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2025-8727 | HIGH | 7.2 | 0.3% | Nov 18, 2025 | There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web ... |
| CVE-2025-8076 | HIGH | 7.2 | 0.3% | Nov 18, 2025 | There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web ... |
| CVE-2025-10089 | HIGH | 7.7 | 0.1% | Nov 18, 2025 | Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S ... |
| CVE-2025-48593 | HIGH | 8 | 0.9% | Nov 18, 2025 | In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. Th... |
| CVE-2025-12974 | HIGH | 8.1 | 0.6% | Nov 18, 2025 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-8693 | HIGH | 8.8 | 1.0% | Nov 18, 2025 | A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(A... |
| CVE-2025-6599 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | An uncontrolled resource consumption vulnerability in the web server of Zyxel DX3301-T0 firmware version 5.50(ABVY.6.3)C... |
| CVE-2025-13325 | HIGH | 8.8 | 0.3% | Nov 18, 2025 | A vulnerability was determined in itsourcecode Student Information System 1.0. The affected element is an unknown functi... |
| CVE-2025-13306 | HIGH | 8.8 | 7.2% | Nov 18, 2025 | A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the fu... |
| CVE-2025-13230 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-13229 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-13228 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru... |
| CVE-2025-13227 | HIGH | 8.8 | 0.2% | Nov 18, 2025 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corru... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now