2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12169 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-12085 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-12023 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-12022 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-11368 | MEDIUM | 5.3 | 0.9% | Nov 21, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Sensitive Information Disclosure in all vers... |
| CVE-2025-62426 | MEDIUM | 6.5 | 0.3% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, the /v1/c... |
| CVE-2025-62372 | MEDIUM | 6.5 | 0.3% | Nov 21, 2025 | vLLM is an inference and serving engine for large language models (LLMs). From version 0.5.5 to before 0.11.1, users can... |
| CVE-2025-62459 | MEDIUM | 6.1 | 0.3% | Nov 20, 2025 | Microsoft Defender Portal Spoofing Vulnerability |
| CVE-2025-13484 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | A vulnerability was identified in Campcodes Complete Online Beauty Parlor Management System 1.0. This vulnerability affe... |
| CVE-2025-36159 | MEDIUM | 5.5 | 0.1% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a local user to forge log files to impersonate other users or hide their ide... |
| CVE-2025-36158 | MEDIUM | 5.5 | 0.1% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 could allow a local user with specific permission to obtain sensitive information from f... |
| CVE-2025-36153 | MEDIUM | 6.1 | 0.2% | Nov 20, 2025 | IBM Concert 1.0.0 through 2.0.0 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated atta... |
| CVE-2025-55124 | MEDIUM | 6.1 | 0.4% | Nov 20, 2025 | Improper neutralisation of input in Revive Adserver 6.0.0+ causes a reflected XSS attack in the banner-zone.php script. |
| CVE-2025-55123 | MEDIUM | 5.4 | 0.4% | Nov 20, 2025 | Improper neutralization of input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes manager accounts to be a... |
| CVE-2025-52671 | MEDIUM | 4.3 | 0.4% | Nov 20, 2025 | Debug information disclosure in the SQL error message to in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes ... |
| CVE-2025-52670 | MEDIUM | 6.5 | 0.3% | Nov 20, 2025 | Missing authorization check in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes users on the system to delete... |
| CVE-2025-52669 | MEDIUM | 4.3 | 0.3% | Nov 20, 2025 | Insecure design policies in the user management system of Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes no... |
| CVE-2025-52668 | MEDIUM | 5.4 | 0.5% | Nov 20, 2025 | Improper input neutralization in the stats-conversions.php script in Revive Adserver 5.5.2 and 6.0.1 and earlier version... |
| CVE-2025-52667 | MEDIUM | 5.4 | 0.4% | Nov 20, 2025 | Missing JSON Content-Type header in a script in Revive Adserver 6.0.1 and 5.5.2 and earlier versions causes a stored XSS... |
| CVE-2025-48987 | MEDIUM | 6.1 | 0.5% | Nov 20, 2025 | Improper Neutralization of Input in Revive Adserver 5.5.2 and 6.0.1 and earlier versions causes a potential reflected XS... |
| CVE-2025-35029 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | Medical Informatics Engineering Enterprise Health has a stored cross site scripting vulnerability that allows an authent... |
| CVE-2025-55128 | MEDIUM | 6.5 | 0.4% | Nov 20, 2025 | HackerOne community member Dang Hung Vi (vidang04) has reported an uncontrolled resource consumption vulnerability in th... |
| CVE-2025-55127 | MEDIUM | 5.4 | 0.2% | Nov 20, 2025 | HackerOne community member Dao Hoang Anh (yoyomiski) has reported an improper neutralization of whitespace in the userna... |
| CVE-2025-55126 | MEDIUM | 6.5 | 0.2% | Nov 20, 2025 | HackerOne community member Dang Hung Vi (vidang04) has reported a stored XSS vulnerability involving the navigation box ... |
| CVE-2025-64524 | MEDIUM | 5.5 | 0.2% | Nov 20, 2025 | cups-filters contains backends, filters, and other software required to get the cups printing service working on operati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now