2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58307 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-58303 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | UAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-58294 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2025-66361 | MEDIUM | 6.5 | 0.2% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p... |
| CVE-2025-66359 | MEDIUM | 6.1 | 0.2% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl... |
| CVE-2025-12559 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em... |
| CVE-2025-13765 | MEDIUM | 4.3 | 0.3% | Nov 27, 2025 | Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De... |
| CVE-2025-12971 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul... |
| CVE-2025-59454 | MEDIUM | 4.3 | 0.3% | Nov 27, 2025 | In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour... |
| CVE-2025-59302 | MEDIUM | 4.7 | 0.4% | Nov 27, 2025 | In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following ... |
| CVE-2025-54057 | MEDIUM | 6.1 | 0.6% | Nov 27, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This ... |
| CVE-2025-13742 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used ... |
| CVE-2025-10476 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-59026 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend... |
| CVE-2025-59025 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us... |
| CVE-2025-30190 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can ... |
| CVE-2025-30186 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend... |
| CVE-2025-13381 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to unauthorized access due t... |
| CVE-2025-13378 | MEDIUM | 6.5 | 0.2% | Nov 27, 2025 | The AI ChatBot with ChatGPT and Content Generator by AYS plugin for WordPress is vulnerable to Server-Side Request Forge... |
| CVE-2025-12584 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and inc... |
| CVE-2025-13441 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Hide Category by User Role for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in all versio... |
| CVE-2025-13157 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The QODE Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions... |
| CVE-2025-13525 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | The WP Directory Kit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'order_by' parameter i... |
| CVE-2025-13143 | MEDIUM | 4.3 | 0.1% | Nov 27, 2025 | The Poll, Survey & Quiz Maker Plugin by Opinion Stage plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2025-12185 | MEDIUM | 4.4 | 0.2% | Nov 27, 2025 | The StaffList plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now