2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13589 | MEDIUM | 5.1 | 0.4% | Nov 24, 2025 | FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthentica... |
| CVE-2025-13577 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the fil... |
| CVE-2025-12800 | MEDIUM | 6.4 | 0.2% | Nov 23, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all ... |
| CVE-2025-13566 | MEDIUM | 4.8 | 0.1% | Nov 23, 2025 | A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_... |
| CVE-2025-13318 | MEDIUM | 5.3 | 0.3% | Nov 22, 2025 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and... |
| CVE-2025-13136 | MEDIUM | 4.3 | 0.2% | Nov 22, 2025 | The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-13317 | MEDIUM | 5.3 | 0.2% | Nov 22, 2025 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ... |
| CVE-2025-12877 | MEDIUM | 5.3 | 0.2% | Nov 22, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod... |
| CVE-2025-12752 | MEDIUM | 5.3 | 0.1% | Nov 22, 2025 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u... |
| CVE-2025-11186 | MEDIUM | 6.4 | 0.2% | Nov 22, 2025 | The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-12889 | MEDIUM | 5.4 | 0.1% | Nov 22, 2025 | With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those ... |
| CVE-2025-11936 | MEDIUM | 5.3 | 0.4% | Nov 21, 2025 | Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u... |
| CVE-2025-11933 | MEDIUM | 6.5 | 0.4% | Nov 21, 2025 | Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows... |
| CVE-2025-11932 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info... |
| CVE-2025-65111 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to ... |
| CVE-2025-65107 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from... |
| CVE-2025-65092 | MEDIUM | 6.9 | 0.3% | Nov 21, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the E... |
| CVE-2025-43374 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad... |
| CVE-2025-31266 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f... |
| CVE-2025-31248 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2025-0504 | MEDIUM | 5.4 | 0.1% | Nov 21, 2025 | Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with th... |
| CVE-2025-36149 | MEDIUM | 5.4 | 0.2% | Nov 21, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim. |
| CVE-2025-13524 | MEDIUM | 6.8 | 0.2% | Nov 21, 2025 | Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linu... |
| CVE-2025-64169 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to befo... |
| CVE-2025-54866 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to befo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now