2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62689 | HIGH | 8.7 | 0.4% | Nov 10, 2025 | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co... |
| CVE-2025-59777 | HIGH | 8.7 | 0.4% | Nov 10, 2025 | NULL pointer dereference vulnerability exists in GNU libmicrohttpd v1.0.2 and earlier. The vulnerability was fixed in co... |
| CVE-2025-12613 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | Versions of the package cloudinary before 2.7.0 are vulnerable to Arbitrary Argument Injection due to improper parsing o... |
| CVE-2025-12867 | HIGH | 8.6 | 0.6% | Nov 10, 2025 | EIP Plus developed by Hundred Plus has an Arbitrary File Uplaod vulnerability, allowing privileged remote attackers to u... |
| CVE-2025-12927 | HIGH | 7.2 | 0.3% | Nov 10, 2025 | A security vulnerability has been detected in DedeBIZ up to 6.3.2. The impacted element is an unknown function of the fi... |
| CVE-2025-12926 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | A weakness has been identified in SourceCodester Farm Management System 1.0. The affected element is an unknown function... |
| CVE-2025-12865 | HIGH | 8.8 | 0.3% | Nov 10, 2025 | U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to in... |
| CVE-2025-12864 | HIGH | 8.8 | 0.4% | Nov 10, 2025 | U-Office Force developed by e-Excellence has a SQL Injection vulnerability, allowing authenticated remote attacker to in... |
| CVE-2025-12922 | HIGH | 8.8 | 0.5% | Nov 10, 2025 | A vulnerability was found in OpenClinica Community Edition up to 3.12.2/3.13. This affects an unknown part of the file /... |
| CVE-2025-12921 | HIGH | 8.8 | 0.5% | Nov 10, 2025 | A vulnerability has been found in OpenClinica Community Edition up to 3.12.2/3.13. Affected by this issue is some unknow... |
| CVE-2025-12399 | HIGH | 7.2 | 0.6% | Nov 8, 2025 | The Alex Reservations: Smart Restaurant Booking plugin for WordPress is vulnerable to arbitrary file uploads due to miss... |
| CVE-2025-11967 | HIGH | 7.2 | 0.5% | Nov 8, 2025 | The Mail Mint plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the pr... |
| CVE-2025-12099 | HIGH | 7.2 | 0.5% | Nov 8, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to PHP Object ... |
| CVE-2025-9334 | HIGH | 8.8 | 0.5% | Nov 8, 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to Limited Code Injection in all... |
| CVE-2025-12161 | HIGH | 8.8 | 0.5% | Nov 8, 2025 | The Smart Auto Upload Images plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type valid... |
| CVE-2025-11452 | HIGH | 7.5 | 0.3% | Nov 8, 2025 | The Asgaros Forum plugin for WordPress is vulnerable to SQL Injection via the '$_COOKIE['asgarosforum_unread_exclude']' ... |
| CVE-2025-64496 | HIGH | 8 | 7.8% | Nov 8, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Versions 0.6.224 and ... |
| CVE-2025-64492 | HIGH | 8.8 | 0.3% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0... |
| CVE-2025-64490 | HIGH | 8.3 | 0.2% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.... |
| CVE-2025-64489 | HIGH | 8.8 | 0.3% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.... |
| CVE-2025-64488 | HIGH | 8.8 | 0.4% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.... |
| CVE-2025-12907 | HIGH | 8.8 | 0.3% | Nov 8, 2025 | Insufficient validation of untrusted input in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker... |
| CVE-2025-37736 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | Improper Authorization in Elastic Cloud Enterprise can lead to Privilege Escalation where the built-in readonly user can... |
| CVE-2025-60574 | HIGH | 7.5 | 0.4% | Nov 7, 2025 | A Local File Inclusion (LFI) vulnerability has been identified in tQuadra CMS 4.2.1117. The issue exists in the "/styles... |
| CVE-2025-64439 | HIGH | 7.4 | 0.9% | Nov 7, 2025 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now