2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-31266 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | A spoofing issue was addressed with improved truncation when displaying the fully qualified domain name. This issue is f... |
| CVE-2025-31248 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m... |
| CVE-2025-0504 | MEDIUM | 5.4 | 0.1% | Nov 21, 2025 | Black Duck SCA versions prior to 2025.10.0 had user role permissions configured in an overly broad manner. Users with th... |
| CVE-2025-36149 | MEDIUM | 5.4 | 0.2% | Nov 21, 2025 | IBM Concert Software 1.0.0 through 2.0.0 could allow a remote attacker to hijack the clicking action of the victim. |
| CVE-2025-13524 | MEDIUM | 6.8 | 0.2% | Nov 21, 2025 | Improper resource release in the call termination process in AWS Wickr before version 6.62.13 on Windows, macOS and Linu... |
| CVE-2025-64169 | MEDIUM | 4.9 | 0.3% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 3.7.0 to befo... |
| CVE-2025-54866 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to befo... |
| CVE-2025-48502 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting ... |
| CVE-2025-29934 | MEDIUM | 5.3 | 0.1% | Nov 21, 2025 | A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries,... |
| CVE-2025-64483 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the ... |
| CVE-2025-12747 | MEDIUM | 5.3 | 0.3% | Nov 21, 2025 | The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via ... |
| CVE-2025-13432 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise w... |
| CVE-2025-66115 | MEDIUM | 6.6 | 0.4% | Nov 21, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-66114 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variat... |
| CVE-2025-66113 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploit... |
| CVE-2025-66112 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting In... |
| CVE-2025-66111 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nelio Software Nel... |
| CVE-2025-66110 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66109 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Expl... |
| CVE-2025-66108 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploitin... |
| CVE-2025-66107 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-f... |
| CVE-2025-66106 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting ... |
| CVE-2025-66101 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly C... |
| CVE-2025-66099 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in ThemeAtelier Chat Help chat-help allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-66098 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Camille V Traveler... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now