2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9223 | HIGH | 8.8 | 3.9% | Nov 11, 2025 | Zohocorp ManageEngine Applications Manager versions 178100 and below are vulnerable to authenticated command injection v... |
| CVE-2025-11862 | HIGH | 8.4 | 0.3% | Nov 11, 2025 | A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and de... |
| CVE-2025-11697 | HIGH | 8.9 | 0.1% | Nov 11, 2025 | A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability a... |
| CVE-2025-11696 | HIGH | 8.9 | 0.1% | Nov 11, 2025 | A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. ... |
| CVE-2025-11085 | HIGH | 8.6 | 0.3% | Nov 11, 2025 | A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in t... |
| CVE-2025-11084 | HIGH | 7.6 | 0.1% | Nov 11, 2025 | A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a val... |
| CVE-2025-10161 | HIGH | 7.3 | 0.2% | Nov 11, 2025 | Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on ... |
| CVE-2025-12846 | HIGH | 8.8 | 0.6% | Nov 11, 2025 | The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a... |
| CVE-2025-10714 | HIGH | 8.4 | 0.1% | Nov 11, 2025 | AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala... |
| CVE-2025-11855 | HIGH | 7.5 | 0.2% | Nov 11, 2025 | The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportReques... |
| CVE-2025-11307 | HIGH | 8.8 | 1.9% | Nov 11, 2025 | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJA... |
| CVE-2025-12637 | HIGH | 8.8 | 0.5% | Nov 11, 2025 | The Elastic Theme Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a dynamic code generation f... |
| CVE-2025-11521 | HIGH | 8.1 | 0.4% | Nov 11, 2025 | The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to i... |
| CVE-2025-11451 | HIGH | 7.5 | 0.4% | Nov 11, 2025 | The Auto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to arbitrary files reads i... |
| CVE-2025-11168 | HIGH | 8.8 | 0.3% | Nov 11, 2025 | The Mementor Core plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.2.5... |
| CVE-2025-42940 | HIGH | 7.5 | 0.4% | Nov 11, 2025 | SAP CommonCryptoLib does not perform necessary boundary checks during pre-authentication parsing of manipulated ASN.1 da... |
| CVE-2025-64522 | HIGH | 7.6 | 0.3% | Nov 10, 2025 | Soft Serve is a self-hostable Git server for the command line. Versions prior to 0.11.1 have a SSRF vulnerability where ... |
| CVE-2025-64519 | HIGH | 8.8 | 0.4% | Nov 10, 2025 | TorrentPier is an open source BitTorrent Public/Private tracker engine, written in php. In versions up to and including ... |
| CVE-2025-63678 | HIGH | 7.2 | 0.4% | Nov 10, 2025 | An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manage... |
| CVE-2025-11578 | HIGH | 7.2 | 0.6% | Nov 10, 2025 | A privilege escalation vulnerability was identified in GitHub Enterprise Server that allowed an authenticated Enterprise... |
| CVE-2025-64518 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | The CycloneDX core module provides a model representation of the SBOM along with utilities to assist in creating, valida... |
| CVE-2025-64512 | HIGH | 7.8 | 0.3% | Nov 10, 2025 | Pdfminer.six is a community maintained fork of the original PDFMiner, a tool for extracting information from PDF documen... |
| CVE-2025-64509 | HIGH | 7.5 | 0.3% | Nov 10, 2025 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.6, a specially crafted Brotli-compressed envelope... |
| CVE-2025-64508 | HIGH | 7.5 | 0.4% | Nov 10, 2025 | Bugsink is a self-hosted error tracking tool. In versions prior to 2.0.5, brotli "bombs" (highly compressed brotli strea... |
| CVE-2025-64507 | HIGH | 7.8 | 0.1% | Nov 10, 2025 | Incus is a system container and virtual machine manager. An issue in versions prior to 6.0.6 and 6.19.0 affects any Incu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now