2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13945 | MEDIUM | 5.5 | 0.1% | Dec 3, 2025 | HTTP3 dissector crash in Wireshark 4.6.0 and 4.6.1 allows denial of service |
| CVE-2025-13495 | MEDIUM | 4.9 | 0.3% | Dec 3, 2025 | The FluentCart plugin for WordPress is vulnerable to SQL Injection via the 'groupKey' parameter in all versions up to, a... |
| CVE-2025-12585 | MEDIUM | 5.3 | 0.3% | Dec 3, 2025 | The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio... |
| CVE-2025-10304 | MEDIUM | 5.3 | 0.2% | Dec 3, 2025 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u... |
| CVE-2025-13646 | MEDIUM | 6.6 | 0.7% | Dec 3, 2025 | The Modula Image Gallery plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validatio... |
| CVE-2025-13448 | MEDIUM | 6.4 | 0.2% | Dec 3, 2025 | The CSSIgniter Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'element' shortcode ... |
| CVE-2025-65955 | MEDIUM | 6.1 | 0.1% | Dec 2, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.... |
| CVE-2025-55181 | MEDIUM | 5.3 | 0.3% | Dec 2, 2025 | Sending an HTTP request/response body with greater than 2^31 bytes triggers an infinite loop in proxygen::coro::HTTPQuic... |
| CVE-2025-65657 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | FeehiCMS version 2.1.1 has a Remote Code Execution via Unrestricted File Upload in Ad Management. FeehiCMS version 2.1.1... |
| CVE-2025-65380 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the admin/index.php endpoint. Specifically, the username... |
| CVE-2025-65379 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | PHPGurukul Billing System 1.0 is vulnerable to SQL Injection in the /admin/password-recovery.php endpoint. Specifically,... |
| CVE-2025-66468 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | The Aimeos GrapesJS CMS extension provides page editor for creating content pages based on extensible components. Prior ... |
| CVE-2025-66460 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66459 | MEDIUM | 6.1 | 0.3% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66458 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call eac... |
| CVE-2025-66454 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | Arcade MCP allows you to to create, deploy, and share MCP Servers. Prior to 1.5.4, the arcade-mcp HTTP server uses a har... |
| CVE-2025-57850 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | A container privilege escalation flaw was found in certain CodeReady Workspaces images. This issue stems from the /etc/p... |
| CVE-2025-13637 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convince... |
| CVE-2025-13636 | MEDIUM | 4.3 | 0.2% | Dec 2, 2025 | Inappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinc... |
| CVE-2025-13635 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome prior to 143.0.7499.41 allowed a local attacker to perform UI... |
| CVE-2025-13634 | MEDIUM | 4.4 | 0.1% | Dec 2, 2025 | Inappropriate implementation in Downloads in Google Chrome on Windows prior to 143.0.7499.41 allowed a local attacker to... |
| CVE-2025-13632 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 143.0.7499.41 allowed an attacker who convinced a use... |
| CVE-2025-65881 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Sourcecodester Zoo Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /classes/Login.php. |
| CVE-2025-65215 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Sourcecodester Web-based Pharmacy Product Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in /product... |
| CVE-2025-65105 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Apptainer is an open source container platform. In Apptainer versions less than 1.4.5, a container can disable two of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now