2025 CVE Vulnerabilities
45,144 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64730 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary s... |
| CVE-2025-64304 | MEDIUM | 5.1 | 0.1% | Nov 25, 2025 | "FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptogra... |
| CVE-2025-62497 | MEDIUM | 6.5 | 0.1% | Nov 25, 2025 | Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a speciall... |
| CVE-2025-13558 | MEDIUM | 5.4 | 0.2% | Nov 25, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-12893 | MEDIUM | 5.4 | 0.1% | Nov 25, 2025 | Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align... |
| CVE-2025-10646 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capabil... |
| CVE-2025-65944 | MEDIUM | 5.1 | 0.3% | Nov 25, 2025 | Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js appl... |
| CVE-2025-64506 | MEDIUM | 6.1 | 0.1% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64505 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-10144 | MEDIUM | 6.5 | 0.2% | Nov 24, 2025 | The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri... |
| CVE-2025-63674 | MEDIUM | 6.8 | 0.3% | Nov 24, 2025 | An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary c... |
| CVE-2025-54341 | MEDIUM | 5.3 | 0.2% | Nov 24, 2025 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Ha... |
| CVE-2025-63498 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. |
| CVE-2025-48511 | MEDIUM | 5.5 | 0.1% | Nov 24, 2025 | Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti... |
| CVE-2025-29933 | MEDIUM | 5.5 | 0.1% | Nov 24, 2025 | Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a... |
| CVE-2025-0007 | MEDIUM | 5.7 | 0.1% | Nov 24, 2025 | Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user s... |
| CVE-2025-64048 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulner... |
| CVE-2025-64047 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php. |
| CVE-2025-63914 | MEDIUM | 6.5 | 0.3% | Nov 24, 2025 | An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.... |
| CVE-2025-36112 | MEDIUM | 5.3 | 0.2% | Nov 24, 2025 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7 and 6.2.0.0 through 6.2.0.5 and 6.2.1.... |
| CVE-2025-13466 | MEDIUM | 5.5 | 0.3% | Nov 24, 2025 | body-parser 2.2.0 is vulnerable to denial of service due to inefficient handling of URL-encoded bodies with very large n... |
| CVE-2025-63953 | MEDIUM | 6.5 | 0.1% | Nov 24, 2025 | A Cross-Site Request Forgery (CSRF) in the /usapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta... |
| CVE-2025-63952 | MEDIUM | 5.7 | 0.1% | Nov 24, 2025 | A Cross-Site Request Forgery (CSRF) in the /mwapi?method=add-user component of Magewell Pro Convert v1.2.213 allows atta... |
| CVE-2025-63435 | MEDIUM | 4.3 | 0.3% | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 is Missing Authentication for Critical Function. The server-side end... |
| CVE-2025-63433 | MEDIUM | 4.6 | 0.2% | Nov 24, 2025 | Xtooltech Xtool AnyScan Android Application 4.40.40 and prior uses a hardcoded cryptographic key and IV to decrypt updat... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now