2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64750 | MEDIUM | 4.5 | 0.1% | Dec 2, 2025 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.3.5 and SingularityPRO 4.... |
| CVE-2025-52622 | MEDIUM | 5.4 | 0.1% | Dec 2, 2025 | The BigFix SaaS's HTTP responses were missing some security headers. The absence of these headers weakens the applicatio... |
| CVE-2025-65186 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Grav CMS 1.7.49 is vulnerable to Cross Site Scripting (XSS). The page editor allows authenticated users to edit page con... |
| CVE-2025-64070 | MEDIUM | 5.4 | 0.2% | Dec 2, 2025 | Sourcecodester Student Grades Management System v1.0 is vulnerable to Cross Site Scripting (XSS) in the Add New Subject ... |
| CVE-2025-65187 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | A Stored Cross Site Scripting vulnerability exists in CiviCRM before v6.7 in the Accounting Batches field. An authentica... |
| CVE-2025-63872 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | DeepSeek V3.2 has a Cross Site Scripting (XSS) vulnerability, which allows JavaScript execution through model-generated ... |
| CVE-2025-59704 | MEDIUM | 4.6 | 0.2% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-58113 | MEDIUM | 6.5 | 0.3% | Dec 2, 2025 | An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Co. Ltd PDF-XChange Editor 10.7.3.401... |
| CVE-2025-13877 | MEDIUM | 5.6 | 0.3% | Dec 2, 2025 | A vulnerability was detected in nocobase up to 1.9.4/2.0.0-alpha.37. The affected element is an unknown function of the ... |
| CVE-2025-13372 | MEDIUM | 4.3 | 0.9% | Dec 2, 2025 | An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. `FilteredRelation` is subject to ... |
| CVE-2025-12630 | MEDIUM | 4.9 | 0.3% | Dec 2, 2025 | The Upload.am WordPress plugin before 1.0.1 is vulnerable to arbitrary option disclosure due to a missing capability ch... |
| CVE-2025-59705 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59701 | MEDIUM | 4.1 | 0.2% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59699 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59698 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (... |
| CVE-2025-59694 | MEDIUM | 6.8 | 0.3% | Dec 2, 2025 | The Chassis Management Board in Entrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patch... |
| CVE-2025-13875 | MEDIUM | 6.3 | 0.4% | Dec 2, 2025 | A weakness has been identified in Yohann0617 oci-helper up to 3.2.4. This issue affects the function addCfg of the file ... |
| CVE-2025-13505 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting'), Improper Neutralization of ... |
| CVE-2025-41086 | MEDIUM | 6.5 | 0.2% | Dec 2, 2025 | Vulnerability in the access control system of the GAMS licensing system that allows unlimited valid licenses to be gener... |
| CVE-2025-41066 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Horde Groupware v5.2.22 has a user enumeration vulnerability that allows an unauthenticated attacker to determine the ex... |
| CVE-2025-13731 | MEDIUM | 6.4 | 0.2% | Dec 2, 2025 | The Nexter Extension – Site Enhancements Toolkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-41012 | MEDIUM | 5.3 | 0.2% | Dec 2, 2025 | Unauthorized access vulnerability in TCMAN GIM v11 version 20250304. This vulnerability allows an unauthenticated attack... |
| CVE-2025-40700 | MEDIUM | 6.1 | 0.2% | Dec 2, 2025 | Reflected Cross-Site Scripting (XSS) in IDI Eikon's Governalia. The vulnerability allows an attacker to execute JavaScri... |
| CVE-2025-13090 | MEDIUM | 4.9 | 0.3% | Dec 2, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up t... |
| CVE-2025-41743 | MEDIUM | 4 | 0.1% | Dec 2, 2025 | Insufficient encryption strength in Sprecher Automation SPRECON-E-C, SPRECON-E-P, and SPRECON-E-T3 allows a local unpriv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now