2025 CVE Vulnerabilities
45,143 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13877 | MEDIUM | 5.6 | 0.3% | Dec 2, 2025 | A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the ... |
| CVE-2025-13372 | MEDIUM | 4.3 | 0.9% | Dec 2, 2025 | An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to ... |
| CVE-2025-12630 | MEDIUM | 4.9 | 0.2% | Dec 2, 2025 | The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability ch... |
| CVE-2025-59705 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a Physically Proximate Attacker... |
| CVE-2025-59701 | MEDIUM | 4.1 | 0.2% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker... |
| CVE-2025-59699 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow a physically proximate attacker... |
| CVE-2025-59698 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, might allow a physically proximate at... |
| CVE-2025-59694 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7, allow... |
| CVE-2025-13875 | MEDIUM | 6.3 | 0.3% | Dec 2, 2025 | A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file ... |
| CVE-2025-13505 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of ... |
| CVE-2025-41086 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be gener... |
| CVE-2025-41066 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the ex... |
| CVE-2025-13731 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-41012 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attack... |
| CVE-2025-40700 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScri... |
| CVE-2025-13090 | MEDIUM | 4.9 | 0.3% | Dec 2, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t... |
| CVE-2025-41743 | MEDIUM | 4 | 0.1% | Dec 2, 2025 | Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unpriv... |
| CVE-2025-13353 | MEDIUM | 5.5 | 0.1% | Dec 2, 2025 | In gokey versions <0.2.0, a flaw in the seed decryption logic resulted in passwords incorrectly being derived solely f... |
| CVE-2025-13873 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Stored Cross-Site Scripting (XSS) in the survey-import feature of ObjectPlanet Opinio 7.26 rev12562 on web application a... |
| CVE-2025-13870 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files ... |
| CVE-2025-10543 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | In Eclipse Paho Go MQTT v3.1 library (paho.mqtt.golang) versions <=1.5.0 UTF-8 encoded strings, passed into the library,... |
| CVE-2025-13696 | MEDIUM | 5.3 | 0.3% | Dec 2, 2025 | The Zigaform plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to, and including, 7.6.... |
| CVE-2025-11726 | MEDIUM | 4.3 | 0.3% | Dec 2, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Missing Authorization in all versions ... |
| CVE-2025-13685 | MEDIUM | 4.3 | 0.1% | Dec 2, 2025 | The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-13140 | MEDIUM | 4.3 | 0.1% | Dec 2, 2025 | The SurveyJS: Drag & Drop WordPress Form Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now