2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-33192 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in SROOT firmware, where an attacker could cause an arbitrary memory read... |
| CVE-2025-33191 | MEDIUM | 5.5 | 0.1% | Nov 25, 2025 | NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read.... |
| CVE-2025-64061 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | Primakon Pi Portal 1.0.18 /api/v2/users endpoint is vulnerable to unauthorized data exposure due to deficient access con... |
| CVE-2025-64049 | MEDIUM | 4.8 | 0.3% | Nov 25, 2025 | A stored cross-site scripting (XSS) vulnerability in the module management component in REDAXO CMS 5.20.0 allows remote ... |
| CVE-2025-13467 | MEDIUM | 5.5 | 0.4% | Nov 25, 2025 | A flaw was found in the Keycloak LDAP User Federation provider. This vulnerability allows an authenticated realm adminis... |
| CVE-2025-59485 | MEDIUM | 4.8 | 0.1% | Nov 25, 2025 | Incorrect default permissions issue exists in Security Point (Windows) of MaLion prior to Ver.5.3.4. If this vulnerabili... |
| CVE-2025-59372 | MEDIUM | 6.9 | 0.6% | Nov 25, 2025 | A path traversal vulnerability has been identified in certain router models. A remote, authenticated attacker could expl... |
| CVE-2025-59369 | MEDIUM | 5.9 | 0.4% | Nov 25, 2025 | A SQL injection vulnerability has been identified in bwdpi. A remote, authenticated attacker could leverage this vulnera... |
| CVE-2025-59368 | MEDIUM | 6 | 0.4% | Nov 25, 2025 | An integer underflow vulnerability has been identified in Aicloud. An authenticated attacker may trigger this vulnerabil... |
| CVE-2025-59365 | MEDIUM | 6.9 | 0.4% | Nov 25, 2025 | A stack buffer overflow vulnerability has been identified in certain router models. An authenticated attacker may trigge... |
| CVE-2025-13452 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to Missing Au... |
| CVE-2025-13414 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Chamber Dashboard Business Directory plugin for WordPress is vulnerable to unauthorized data export due to a missing... |
| CVE-2025-13405 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Ace Post Type Builder plugin for WordPress is vulnerable to unauthorized custom taxonomy deletion due to missing aut... |
| CVE-2025-13404 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The atec Duplicate Page & Post plugin for WordPress is vulnerable to unauthorized post duplication due to missing author... |
| CVE-2025-13389 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Admin and Customer Messages After Order for WooCommerce: OrderConvo plugin for WordPress is vulnerable to unauthoriz... |
| CVE-2025-13386 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Social Images Widget plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabi... |
| CVE-2025-13385 | MEDIUM | 4.9 | 0.3% | Nov 25, 2025 | The Bookme – Free Online Appointment Booking and Scheduling Plugin for WordPress is vulnerable to time-based SQL Injecti... |
| CVE-2025-13383 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | The Job Board by BestWebSoft plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, an... |
| CVE-2025-13382 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Frontend File Manager Plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2025-13380 | MEDIUM | 6.5 | 0.5% | Nov 25, 2025 | The AI Engine for WordPress: ChatGPT, GPT Content Generator plugin for WordPress is vulnerable to Arbitrary File Read in... |
| CVE-2025-13370 | MEDIUM | 4.9 | 0.3% | Nov 25, 2025 | The ProjectList plugin for WordPress is vulnerable to time-based SQL Injection via the 'id' parameter in all versions up... |
| CVE-2025-13311 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The Just Highlight plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Highlight Color' setting i... |
| CVE-2025-12645 | MEDIUM | 6.4 | 0.2% | Nov 25, 2025 | The Inline frame – Iframe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embedsite' shortcod... |
| CVE-2025-12634 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Refund Request for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2025-12587 | MEDIUM | 4.3 | 0.1% | Nov 25, 2025 | The Peer Publish plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now