2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13443 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | A vulnerability was detected in macrozheng mall up to 1.0.3. Affected by this issue is the function delete of the file /... |
| CVE-2025-12778 | MEDIUM | 5.3 | 0.2% | Nov 20, 2025 | The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-12502 | MEDIUM | 6.8 | 0.2% | Nov 20, 2025 | The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2025-13415 | MEDIUM | 5.4 | 0.2% | Nov 19, 2025 | A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php... |
| CVE-2025-58181 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, al... |
| CVE-2025-47914 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the progra... |
| CVE-2025-13412 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn... |
| CVE-2025-13147 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Progress MOVEit Transfer.This issue affects MOVEit Transfer: before ... |
| CVE-2025-63214 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | An issue was discovered in bridgetech VBC Server & Element Manager, firmware version 6.5.0-10 , 6.5.0-9, allowing unauth... |
| CVE-2025-63212 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | GatesAir Flexiva-LX devices on firmware 1.0.13 and 2.0, including models LX100, LX300, LX600, and LX1000, expose sensiti... |
| CVE-2025-51662 | MEDIUM | 5.4 | 0.1% | Nov 19, 2025 | A stored cross-site scripting (XSS) vulnerability is found in the text sharing feature of FileCodeBox version 2.2 and ea... |
| CVE-2025-36371 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | IBM i 7.2, 7.3, 7.4, 7.5, and 7.6 are impacted by obtaining an information vulnerability in the database plan cache impl... |
| CVE-2025-65100 | MEDIUM | 6.9 | 0.3% | Nov 19, 2025 | Isar is an integration system for automated root filesystem generation. In versions 0.11-rc1 and 0.11, defining ISAR_APT... |
| CVE-2025-64759 | MEDIUM | 6.1 | 0.3% | Nov 19, 2025 | Homarr is an open-source dashboard. Prior to version 1.43.3, stored XSS vulnerability exists, allowing the execution of ... |
| CVE-2025-63211 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | Stored cross-site scripting vulnerability in bridgetech VBC Server & Element Manager, firmware versions 6.5.0-9 thru 6.5... |
| CVE-2025-65089 | MEDIUM | 6.5 | 0.3% | Nov 19, 2025 | XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Prior to ver... |
| CVE-2025-65032 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-65031 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an improper authorization flaw in th... |
| CVE-2025-65028 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an insecure direct object reference ... |
| CVE-2025-65020 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-65019 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with outp... |
| CVE-2025-64765 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for rout... |
| CVE-2025-64764 | MEDIUM | 5.4 | 0.4% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feat... |
| CVE-2025-64708 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions,... |
| CVE-2025-64521 | MEDIUM | 4.8 | 0.2% | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now