2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65496 | MEDIUM | 4.3 | 0.2% | Nov 24, 2025 | NULL pointer dereference in coap_dtls_generate_cookie() in src/coap_openssl.c in OISM libcoap 4.3.5 allows remote attack... |
| CVE-2025-41017 | MEDIUM | 6.9 | 0.2% | Nov 24, 2025 | Inadequate access control vulnerability in Davantis DDFUSION v6.177.7, which allows unauthorised actors to retrieve pers... |
| CVE-2025-12628 | MEDIUM | 6.3 | 0.2% | Nov 24, 2025 | The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th... |
| CVE-2025-41087 | MEDIUM | 5.1 | 0.3% | Nov 24, 2025 | Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not pro... |
| CVE-2025-13588 | MEDIUM | 6.3 | 0.2% | Nov 24, 2025 | A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun... |
| CVE-2025-12569 | MEDIUM | 4.7 | 0.2% | Nov 24, 2025 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before ... |
| CVE-2025-12394 | MEDIUM | 5.9 | 0.3% | Nov 24, 2025 | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur... |
| CVE-2025-13589 | MEDIUM | 5.1 | 0.4% | Nov 24, 2025 | FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthentica... |
| CVE-2025-13577 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the fil... |
| CVE-2025-12800 | MEDIUM | 6.4 | 0.2% | Nov 23, 2025 | The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Server-Side Request Forgery in all ... |
| CVE-2025-13566 | MEDIUM | 4.8 | 0.1% | Nov 23, 2025 | A security vulnerability has been detected in jarun nnn up to 5.1. The impacted element is the function show_content_in_... |
| CVE-2025-13318 | MEDIUM | 5.3 | 0.3% | Nov 22, 2025 | The Booking Calendar Contact Form plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and... |
| CVE-2025-13136 | MEDIUM | 4.3 | 0.2% | Nov 22, 2025 | The GSheetConnector For Ninja Forms plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-13317 | MEDIUM | 5.3 | 0.2% | Nov 22, 2025 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and ... |
| CVE-2025-12877 | MEDIUM | 5.3 | 0.2% | Nov 22, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized mod... |
| CVE-2025-12752 | MEDIUM | 5.3 | 0.1% | Nov 22, 2025 | The Subscriptions & Memberships for PayPal plugin for WordPress is vulnerable to fake payment creation in all versions u... |
| CVE-2025-11186 | MEDIUM | 6.4 | 0.2% | Nov 22, 2025 | The Cookie Notice & Compliance for GDPR / CCPA plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-12889 | MEDIUM | 5.4 | 0.1% | Nov 22, 2025 | With TLS 1.2 connections a client can use any digest, specifically a weaker digest that is supported, rather than those ... |
| CVE-2025-11936 | MEDIUM | 5.3 | 0.4% | Nov 21, 2025 | Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote u... |
| CVE-2025-11933 | MEDIUM | 6.5 | 0.4% | Nov 21, 2025 | Improper Input Validation in the TLS 1.3 CKS extension parsing in wolfSSL 5.8.2 and earlier on multiple platforms allows... |
| CVE-2025-11932 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The server previously verified the TLS 1.3 PSK binder using a non-constant time method which could potentially leak info... |
| CVE-2025-65111 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | SpiceDB is an open source database system for creating and managing security-critical application permissions. Prior to ... |
| CVE-2025-65107 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Langfuse is an open source large language model engineering platform. In versions from 2.95.0 to before 2.95.12 and from... |
| CVE-2025-65092 | MEDIUM | 6.9 | 0.3% | Nov 21, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the E... |
| CVE-2025-43374 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 18.5 and iPadOS 18.5, iPad... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now