2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12349 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth... |
| CVE-2025-6251 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi... |
| CVE-2025-12777 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... |
| CVE-2025-12770 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu... |
| CVE-2025-12427 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ... |
| CVE-2025-13225 | MEDIUM | 6 | 0.1% | Nov 19, 2025 | Tanium addressed an arbitrary file deletion vulnerability in TanOS. |
| CVE-2025-65093 | MEDIUM | 5.5 | 3.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based ... |
| CVE-2025-65013 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cros... |
| CVE-2025-65012 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any... |
| CVE-2025-64515 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data ... |
| CVE-2025-54990 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with... |
| CVE-2025-63229 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting ... |
| CVE-2025-63226 | MEDIUM | 5.7 | 0.2% | Nov 18, 2025 | The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking... |
| CVE-2025-63749 | MEDIUM | 6.5 | 0.9% | Nov 18, 2025 | pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter. |
| CVE-2025-63693 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping fo... |
| CVE-2025-61664 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free iss... |
| CVE-2025-61663 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (... |
| CVE-2025-61661 | MEDIUM | 4.8 | 0.2% | Nov 18, 2025 | A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootl... |
| CVE-2025-56499 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary f... |
| CVE-2025-54771 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A use-after-free vulnerability has been identified in the GNU GRUB (Grand Unified Bootloader). The flaw occurs because t... |
| CVE-2025-54770 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability has been identified in the GRUB2 bootloader's network module that poses an immediate Denial of Service (... |
| CVE-2025-54320 | MEDIUM | 4.3 | 0.3% | Nov 18, 2025 | In Ascertia SigningHub through 8.6.8, there is a lack of rate limiting on the invite user function, leading to an email ... |
| CVE-2025-52639 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | HCL Connections is vulnerable to a sensitive information disclosure vulnerability which could allow a user to obtain sen... |
| CVE-2025-37160 | MEDIUM | 6.5 | 0.2% | Nov 18, 2025 | A broken access control (BAC) vulnerability in the web-based management interface could allow an authenticated remote at... |
| CVE-2025-37156 | MEDIUM | 6.8 | 0.3% | Nov 18, 2025 | A platform-level denial-of-service (DoS) vulnerability exists in ArubaOS-CX software. Successful exploitation of this vu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now