2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12921 | HIGH | 8.8 | 0.5% | Nov 10, 2025 | A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknow... |
| CVE-2025-12399 | HIGH | 7.2 | 0.6% | Nov 8, 2025 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss... |
| CVE-2025-11967 | HIGH | 7.2 | 0.5% | Nov 8, 2025 | The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr... |
| CVE-2025-12099 | HIGH | 7.2 | 0.5% | Nov 8, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object ... |
| CVE-2025-9334 | HIGH | 8.8 | 0.4% | Nov 8, 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all... |
| CVE-2025-12161 | HIGH | 8.8 | 0.5% | Nov 8, 2025 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-11452 | HIGH | 7.5 | 0.3% | Nov 8, 2025 | The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' ... |
| CVE-2025-64496 | HIGH | 8 | 7.8% | Nov 8, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and ... |
| CVE-2025-64492 | HIGH | 8.8 | 0.3% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0... |
| CVE-2025-64490 | HIGH | 8.3 | 0.2% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.... |
| CVE-2025-64489 | HIGH | 8.8 | 0.3% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.... |
| CVE-2025-64488 | HIGH | 8.8 | 0.4% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.... |
| CVE-2025-12907 | HIGH | 8.8 | 0.3% | Nov 8, 2025 | Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker... |
| CVE-2025-37736 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can... |
| CVE-2025-60574 | HIGH | 7.5 | 0.4% | Nov 7, 2025 | A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles... |
| CVE-2025-64439 | HIGH | 7.4 | 0.9% | Nov 7, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2025-12875 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | A weakness has been identified in mruby 3.4.0. This vulnerability affects the function ary_fill_exec of the file mrbgems... |
| CVE-2025-64431 | HIGH | 8.7 | 0.3% | Nov 7, 2025 | Zitadel is an open source identity management platform. Versions 4.0.0-rc.1 through 4.6.2 are vulnerable to secure Direc... |
| CVE-2025-36186 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | IBM Db2 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes Db2 Connect Server) under specific configurations co... |
| CVE-2025-33012 | HIGH | 8.8 | 0.1% | Nov 7, 2025 | IBM Db2 10.5.0 through 10.5.11, 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux coul... |
| CVE-2025-2534 | HIGH | 7.5 | 0.2% | Nov 7, 2025 | IBM Db2 11.1.0 through 11.1.4.7, 11.5.0 through 11.5.9, and 12.1.0 through 12.1.3 for Linux, UNIX and Windows (includes ... |
| CVE-2025-9458 | HIGH | 7.8 | 0.2% | Nov 7, 2025 | A maliciously crafted PRT file, when parsed through certain Autodesk products, can force a Memory Corruption vulnerabili... |
| CVE-2025-64430 | HIGH | 7.5 | 0.6% | Nov 7, 2025 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. In versions 4.2.... |
| CVE-2025-64347 | HIGH | 7.5 | 0.3% | Nov 7, 2025 | Apollo Router Core is a configurable Rust graph router written to run a federated supergraph using Apollo Federation 2. ... |
| CVE-2025-57698 | HIGH | 7.5 | 0.7% | Nov 7, 2025 | AstrBot Project v3.5.22 contains a directory traversal vulnerability. The handler function install_plugin_upload of the ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now