2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48502 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting ... |
| CVE-2025-29934 | MEDIUM | 5.3 | 0.1% | Nov 21, 2025 | A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries,... |
| CVE-2025-64483 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the ... |
| CVE-2025-12747 | MEDIUM | 5.3 | 0.3% | Nov 21, 2025 | The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via ... |
| CVE-2025-13432 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise w... |
| CVE-2025-66115 | MEDIUM | 6.6 | 0.4% | Nov 21, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-66114 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variat... |
| CVE-2025-66113 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploit... |
| CVE-2025-66112 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting In... |
| CVE-2025-66111 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nelio Software Nel... |
| CVE-2025-66110 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66109 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Expl... |
| CVE-2025-66108 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploitin... |
| CVE-2025-66107 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-f... |
| CVE-2025-66106 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting ... |
| CVE-2025-66101 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly C... |
| CVE-2025-66099 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-66098 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Traveler... |
| CVE-2025-66097 | MEDIUM | 4.3 | 0.1% | Nov 21, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Igor Jerosimić I Order Terms i-order-terms allows Cross Site Request ... |
| CVE-2025-66096 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Imtiaz Rayhan Table Block by Tableberg tableberg allows Exploiting Incorrectly Co... |
| CVE-2025-66093 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hupe13 Extensions ... |
| CVE-2025-66092 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bqworks Accordion ... |
| CVE-2025-66091 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Design Stylish Cos... |
| CVE-2025-66090 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sonalsinha21 SKT S... |
| CVE-2025-66089 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in WebToffee Product Feed for WooCommerce webtoffee-product-feed allows Exploiting I... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now