2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12666 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin... |
| CVE-2025-12649 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt... |
| CVE-2025-12579 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-12578 | MEDIUM | 4.3 | 0.1% | Nov 27, 2025 | The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-66030 | MEDIUM | 5.3 | 0.3% | Nov 26, 2025 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl... |
| CVE-2025-7449 | MEDIUM | 6.5 | 0.4% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18... |
| CVE-2025-6195 | MEDIUM | 4.3 | 0.3% | Nov 26, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6... |
| CVE-2025-65670 | MEDIUM | 4.3 | 0.2% | Nov 26, 2025 | An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo... |
| CVE-2025-13611 | MEDIUM | 5.3 | 0.2% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha... |
| CVE-2025-12653 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1... |
| CVE-2025-65676 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi... |
| CVE-2025-65675 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi... |
| CVE-2025-65239 | MEDIUM | 4.3 | 0.3% | Nov 26, 2025 | Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.... |
| CVE-2025-65238 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.... |
| CVE-2025-65237 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to e... |
| CVE-2025-63938 | MEDIUM | 6.5 | 0.2% | Nov 26, 2025 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.... |
| CVE-2025-9191 | MEDIUM | 6.3 | 0.2% | Nov 26, 2025 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des... |
| CVE-2025-9163 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ... |
| CVE-2025-13674 | MEDIUM | 5.5 | 0.1% | Nov 26, 2025 | BPv7 dissector crash in Wireshark 4.6.0 allows denial of service |
| CVE-2025-62728 | MEDIUM | 5.4 | 0.3% | Nov 26, 2025 | SQL injection vulnerability in Hive Metastore Server (HMS) when processing delete column statistics requests via the Thr... |
| CVE-2025-59820 | MEDIUM | 6.7 | 0.2% | Nov 26, 2025 | In KDE Krita before 5.2.13, loading a manipulated TGA file could result in a heap-based buffer overflow in plugins/impex... |
| CVE-2025-66026 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | REDAXO is a PHP-based CMS. Prior to version 5.20.1, a reflected Cross-Site Scripting (XSS) vulnerability exists in the M... |
| CVE-2025-66025 | MEDIUM | 4.3 | 0.2% | Nov 26, 2025 | Caido is a web security auditing toolkit. Prior to version 0.53.0, the Markdown renderer used in Caido’s Findings page i... |
| CVE-2025-66021 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | OWASP Java HTML Sanitizer is a configureable HTML Sanitizer written in Java, allowing inclusion of HTML authored by thir... |
| CVE-2025-12848 | MEDIUM | 6.1 | 0.3% | Nov 26, 2025 | Webform Multiple File Upload module for Drupal 7.x contains a cross-site scripting (XSS) vulnerability in the file name ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now