2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49390 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in christophrado Cook... |
| CVE-2025-49386 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | Deserialization of Untrusted Data vulnerability in Scott Reilly Preserve Code Formatting preserve-code-formatting allows... |
| CVE-2025-48330 | HIGH | 7.5 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48290 | HIGH | 8.1 | 0.4% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48090 | HIGH | 8.1 | 0.4% | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in CocoBasic Blanka - One Page WordPress Theme blanka-wp allows PHP Local File... |
| CVE-2025-48085 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ZIPANG Simple Stripe simple-stripe allows Stored XSS.This issue affec... |
| CVE-2025-48083 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in andriassundskard wpNamedUsers wpnamedusers allows Stored XSS.This iss... |
| CVE-2025-48078 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Norbert Slick Google Map slick-google-map allows Stored XSS.This issu... |
| CVE-2025-48077 | HIGH | 7.1 | 0.1% | Nov 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in nitinmaurya12 Block Country block-country allows Stored XSS.This issu... |
| CVE-2025-39468 | HIGH | 8.1 | 0.6% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39467 | HIGH | 8.1 | 0.5% | Nov 6, 2025 | Path Traversal: '.../...//' vulnerability in Mikado-Themes Wanderland wanderland allows PHP Local File Inclusion.This is... |
| CVE-2025-39466 | HIGH | 8.1 | 0.6% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-39463 | HIGH | 7.5 | 0.5% | Nov 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-31029 | HIGH | 7.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bingu replyMail re... |
| CVE-2025-28953 | HIGH | 8.5 | 0.3% | Nov 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in axiomthemes smart ... |
| CVE-2025-12556 | HIGH | 8.8 | 0.4% | Nov 6, 2025 | An argument injection vulnerability exists in the affected product that could allow an attacker to execute arbitrary cod... |
| CVE-2025-37735 | HIGH | 7 | 0.1% | Nov 6, 2025 | Improper preservation of permissions in Elastic Defend on Windows hosts can lead to arbitrary files on the system being ... |
| CVE-2025-11956 | HIGH | 8.9 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-9338 | HIGH | 7.3 | 0.1% | Nov 6, 2025 | A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability... |
| CVE-2025-64171 | HIGH | 8.7 | 0.2% | Nov 6, 2025 | MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n... |
| CVE-2025-55278 | HIGH | 8.1 | 0.2% | Nov 5, 2025 | Improper authentication in the API authentication middleware of HCL DevOps Loop allows authentication tokens to be accep... |
| CVE-2025-12779 | HIGH | 8.8 | 0.2% | Nov 5, 2025 | Improper handling of the authentication token in the Amazon WorkSpaces client for Linux, versions 2023.0 through 2024.8,... |
| CVE-2025-63417 | HIGH | 7.2 | 0.2% | Nov 5, 2025 | A Stored Cross-Site Scripting (XSS) vulnerability in the chat functionality of the SelfBest platform 2023.3 allows authe... |
| CVE-2025-12745 | HIGH | 7.8 | 0.2% | Nov 5, 2025 | A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_a... |
| CVE-2025-11093 | HIGH | 7.2 | 0.4% | Nov 5, 2025 | An arbitrary code execution vulnerability exists in multiple WSO2 products due to insufficient restrictions in the Graal... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now