2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41080 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac... |
| CVE-2025-41079 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | A stored Cross-Site Scripting (XSS) vulnerability has been found in Seafile v12.0.10. This vulnerability allows an attac... |
| CVE-2025-14010 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sen... |
| CVE-2025-12826 | MEDIUM | 4.8 | 0.3% | Dec 4, 2025 | The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,... |
| CVE-2025-12782 | MEDIUM | 4.3 | 0.2% | Dec 4, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2025-13513 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` param... |
| CVE-2025-11379 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and ... |
| CVE-2025-66411 | MEDIUM | 5.5 | 0.2% | Dec 3, 2025 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28... |
| CVE-2025-66406 | MEDIUM | 5 | 0.1% | Dec 3, 2025 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, the... |
| CVE-2025-65345 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality all... |
| CVE-2025-65097 | MEDIUM | 6.5 | 0.2% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-65096 | MEDIUM | 4.3 | 0.2% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-61727 | MEDIUM | 6.5 | 0.3% | Dec 3, 2025 | An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certifi... |
| CVE-2025-50361 | MEDIUM | 5.1 | 0.2% | Dec 3, 2025 | Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db364... |
| CVE-2025-63402 | MEDIUM | 5.5 | 0.3% | Dec 3, 2025 | An issue in HCL Technologies Limited HCLTech GRAGON before v.7.6.0 allows a remote attacker to execute arbitrary code vi... |
| CVE-2025-63401 | MEDIUM | 5.5 | 0.3% | Dec 3, 2025 | Cross Site Scripting vulnerability in HCL Technologies Limited HCLTech DRAGON before v.7.6.0 allows a remote attacker to... |
| CVE-2025-13992 | MEDIUM | 4.7 | 0.2% | Dec 3, 2025 | Side-channel information leakage in Navigation and Loading in Google Chrome prior to 139.0.7258.66 allowed a remote atta... |
| CVE-2025-12084 | MEDIUM | 5.3 | 0.7% | Dec 3, 2025 | When building nested elements using xml.dom.minidom methods such as appendChild() that have a dependency on _clear_id_ca... |
| CVE-2025-64763 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, when Envoy is c... |
| CVE-2025-64527 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy crashes w... |
| CVE-2025-65842 | MEDIUM | 5.1 | 0.1% | Dec 3, 2025 | The Aquarius HelperTool (1.0.003) privileged XPC service on macOS contains multiple flaws that allow local privilege esc... |
| CVE-2025-65841 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | Aquarius Desktop 3.0.069 for macOS stores user authentication credentials in the local file ~/Library/Application Suppor... |
| CVE-2025-62686 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin... |
| CVE-2025-55076 | MEDIUM | 6.2 | 0.2% | Dec 3, 2025 | A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Instal... |
| CVE-2025-53965 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 220... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now