2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12586 | MEDIUM | 4.3 | 0.1% | Nov 25, 2025 | The Conditional Maintenance Mode for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all v... |
| CVE-2025-12525 | MEDIUM | 5.3 | 0.3% | Nov 25, 2025 | The Locker Content plugin for WordPress is vulnerable to Sensitive Information Exposure in version 1.0.0 via the 'locker... |
| CVE-2025-12043 | MEDIUM | 5.3 | 0.2% | Nov 25, 2025 | The Autochat Automatic Conversation plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-12040 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up t... |
| CVE-2025-12032 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The Zweb Social Mobile – Ứng Dụng Nút Gọi Mobile plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-12025 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... |
| CVE-2025-13643 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are bein... |
| CVE-2025-64730 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary s... |
| CVE-2025-64304 | MEDIUM | 5.1 | 0.1% | Nov 25, 2025 | "FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptogra... |
| CVE-2025-62497 | MEDIUM | 6.5 | 0.1% | Nov 25, 2025 | Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a speciall... |
| CVE-2025-13558 | MEDIUM | 5.4 | 0.2% | Nov 25, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-12893 | MEDIUM | 5.4 | 0.1% | Nov 25, 2025 | Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align... |
| CVE-2025-10646 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capabil... |
| CVE-2025-65944 | MEDIUM | 5.1 | 0.3% | Nov 25, 2025 | Sentry-Javascript is an official Sentry SDKs for JavaScript. From version 10.11.0 to before 10.27.0, when a Node.js appl... |
| CVE-2025-64506 | MEDIUM | 6.1 | 0.1% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-64505 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-10144 | MEDIUM | 6.5 | 0.2% | Nov 24, 2025 | The Perfect Brands for WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the `brands` attri... |
| CVE-2025-63674 | MEDIUM | 6.8 | 0.3% | Nov 24, 2025 | An issue in Blurams Lumi Security Camera (A31C) v23.1227.472.2926 allows local physical attackers to execute arbitrary c... |
| CVE-2025-54341 | MEDIUM | 5.3 | 0.2% | Nov 24, 2025 | A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There are Ha... |
| CVE-2025-63498 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | alinto SOGo 5.12.3 is vulnerable to Cross Site Scripting (XSS) via the "userName" parameter. |
| CVE-2025-48511 | MEDIUM | 5.5 | 0.1% | Nov 24, 2025 | Improper input validation within AMD uprof can allow a local attacker to write to an arbitrary physical address, potenti... |
| CVE-2025-29933 | MEDIUM | 5.5 | 0.1% | Nov 24, 2025 | Improper input validation within AMD uProf can allow a local attacker to write out of bounds, potentially resulting in a... |
| CVE-2025-0007 | MEDIUM | 5.7 | 0.1% | Nov 24, 2025 | Insufficient validation within Xilinx Run Time framework could allow a local attacker to escalate privileges from user s... |
| CVE-2025-64048 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | YCCMS 3.4 contains a stored cross-site scripting (XSS) vulnerability in the article management functionality. The vulner... |
| CVE-2025-64047 | MEDIUM | 6.1 | 0.2% | Nov 24, 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /user/user-move.php. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now