2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12123 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | The Customer Reviews Collector for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ... |
| CVE-2025-3784 | MEDIUM | 5.5 | 0.1% | Nov 27, 2025 | Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose creden... |
| CVE-2025-12151 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Simple Folio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'portfolio_name' parameter in... |
| CVE-2025-13762 | MEDIUM | 4.8 | 0.1% | Nov 27, 2025 | Improper Input Validation vulnerability in CyberArk CyberArk Secure Web Sessions Extension on Chrome, Edge allows Denial... |
| CVE-2025-12713 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Soundslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the soundslides shortcode in all v... |
| CVE-2025-12712 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up... |
| CVE-2025-12670 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic... |
| CVE-2025-12666 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin... |
| CVE-2025-12649 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt... |
| CVE-2025-12579 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-12578 | MEDIUM | 4.3 | 0.1% | Nov 27, 2025 | The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-66030 | MEDIUM | 5.3 | 0.3% | Nov 26, 2025 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl... |
| CVE-2025-7449 | MEDIUM | 6.5 | 0.4% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18... |
| CVE-2025-6195 | MEDIUM | 4.3 | 0.3% | Nov 26, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6... |
| CVE-2025-65670 | MEDIUM | 4.3 | 0.2% | Nov 26, 2025 | An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo... |
| CVE-2025-13611 | MEDIUM | 5.3 | 0.2% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 tha... |
| CVE-2025-12653 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.3 before 18.4.5, 18.5 before 18.5.3, and 1... |
| CVE-2025-65676 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi... |
| CVE-2025-65675 | MEDIUM | 5.4 | 0.2% | Nov 26, 2025 | Stored Cross site scripting (XSS) vulnerability in Classroomio LMS 0.1.13 allows authenticated attackers to execute arbi... |
| CVE-2025-65239 | MEDIUM | 4.3 | 0.3% | Nov 26, 2025 | Incorrect access control in the /aux1/ocussd/trace endpoint of OpenCode Systems USSD Gateway OC Release:5, version 6.13.... |
| CVE-2025-65238 | MEDIUM | 6.5 | 0.3% | Nov 26, 2025 | Incorrect access control in the getSubUsersByProvider function of OpenCode Systems USSD Gateway OC Release: 5 Version 6.... |
| CVE-2025-65237 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | A reflected cross-site scripted (XSS) vulnerability in OpenCode Systems USSD Gateway OC Release: 5 allows attackers to e... |
| CVE-2025-63938 | MEDIUM | 6.5 | 0.2% | Nov 26, 2025 | Tinyproxy through 1.11.2 contains an integer overflow vulnerability in the strip_return_port() function within src/reqs.... |
| CVE-2025-9191 | MEDIUM | 6.3 | 0.2% | Nov 26, 2025 | The Houzez theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.1.6 via des... |
| CVE-2025-9163 | MEDIUM | 6.1 | 0.2% | Nov 26, 2025 | The Houzez theme for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now