2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10686 | HIGH | 7.2 | 0.4% | Nov 14, 2025 | The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possib... |
| CVE-2025-13161 | HIGH | 8.7 | 0.5% | Nov 14, 2025 | IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo... |
| CVE-2025-12904 | HIGH | 7.2 | 0.2% | Nov 14, 2025 | The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA... |
| CVE-2025-64530 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions ... |
| CVE-2025-47913 | HIGH | 7.5 | 0.6% | Nov 13, 2025 | SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the cl... |
| CVE-2025-36096 | HIGH | 8.1 | 0.3% | Nov 13, 2025 | IBM AIX 7.2, and 7.3 and IBM VIOS 3.1, and 4.1 stores NIM private keys used in NIM environments in an insecure way which... |
| CVE-2025-13131 | HIGH | 8.5 | 0.1% | Nov 13, 2025 | A vulnerability was found in Sonarr 4.0.15.2940. The impacted element is an unknown function of the file C:\ProgramData\... |
| CVE-2025-13130 | HIGH | 8.5 | 0.1% | Nov 13, 2025 | A vulnerability has been found in Radarr 5.28.0.10274. The affected element is an unknown function of the file C:\Progra... |
| CVE-2025-64726 | HIGH | 7.3 | 0.1% | Nov 13, 2025 | Socket Firewall is an HTTP/HTTPS proxy server that intercepts package manager requests and enforces security policies by... |
| CVE-2025-60679 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210... |
| CVE-2025-59840 | HIGH | 8.1 | 0.3% | Nov 13, 2025 | Vega is a visualization grammar, a declarative format for creating, saving, and sharing interactive visualization design... |
| CVE-2025-46369 | HIGH | 7.8 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contains an Insecure Temporary File vulnerability... |
| CVE-2025-46367 | HIGH | 7.8 | 0.1% | Nov 13, 2025 | Dell Alienware Command Center 6.x (AWCC), versions prior to 6.10.15.0, contain a Detection of Error Condition Without Ac... |
| CVE-2025-63406 | HIGH | 8.8 | 0.6% | Nov 13, 2025 | An issue in Intermesh BV GroupOffice vulnerable before v.25.0.47 and 6.8.136 allows a remote attacker to execute arbitra... |
| CVE-2025-43515 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | The issue was addressed by refusing external connections by default. This issue is fixed in Compressor 4.11.1. An unauth... |
| CVE-2025-64706 | HIGH | 7.5 | 0.2% | Nov 13, 2025 | Typebot is an open-source chatbot builder. In version 3.9.0 up to but excluding version 3.13.0, an Insecure Direct Objec... |
| CVE-2025-60698 | HIGH | 7.3 | 3.4% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-60697 | HIGH | 7.3 | 3.3% | Nov 13, 2025 | A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` a... |
| CVE-2025-12785 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | Certain HP LaserJet Pro printers may be vulnerable to information disclosure leading to credential exposure by altering ... |
| CVE-2025-60696 | HIGH | 8.4 | 0.2% | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_... |
| CVE-2025-60694 | HIGH | 7.5 | 1.3% | Nov 13, 2025 | A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 route... |
| CVE-2025-60692 | HIGH | 8.4 | 0.2% | Nov 13, 2025 | A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmwa... |
| CVE-2025-60691 | HIGH | 8.8 | 0.7% | Nov 13, 2025 | A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.... |
| CVE-2025-60690 | HIGH | 8.8 | 4.4% | Nov 13, 2025 | A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (F... |
| CVE-2025-20349 | HIGH | 8.8 | 0.3% | Nov 13, 2025 | A vulnerability in the REST API of Cisco Catalyst Center could allow an authenticated, remote attacker to execute arbitr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now