2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12497 | HIGH | 8.1 | 0.5% | Nov 5, 2025 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version... |
| CVE-2025-10622 | HIGH | 8 | 0.5% | Nov 5, 2025 | A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set... |
| CVE-2025-64151 | HIGH | 8.4 | 0.1% | Nov 5, 2025 | Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A ... |
| CVE-2025-62225 | HIGH | 8.4 | 0.1% | Nov 5, 2025 | Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use... |
| CVE-2025-12384 | HIGH | 8.6 | 0.3% | Nov 5, 2025 | The Document Embedder – Embed PDFs, Word, Excel, and Other Files plugin for WordPress is vulnerable to unauthorized acce... |
| CVE-2025-12139 | HIGH | 7.5 | 2.2% | Nov 5, 2025 | The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitiv... |
| CVE-2025-21079 | HIGH | 8.1 | 0.4% | Nov 5, 2025 | Improper input validation in Samsung Members prior to version 5.5.01.3 allows remote attackers to connect arbitrary URL ... |
| CVE-2025-21075 | HIGH | 7.5 | 0.2% | Nov 5, 2025 | Out-of-bounds write in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-b... |
| CVE-2025-21074 | HIGH | 7.5 | 0.2% | Nov 5, 2025 | Out-of-bounds read in libimagecodec.quram.so prior to SMR Nov-2025 Release 1 allows remote attackers to access out-of-bo... |
| CVE-2025-12197 | HIGH | 7.5 | 15.2% | Nov 5, 2025 | The The Events Calendar plugin for WordPress is vulnerable to blind SQL Injection via the 's' parameter in versions 6.15... |
| CVE-2025-64110 | HIGH | 7.5 | 0.3% | Nov 5, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen... |
| CVE-2025-64109 | HIGH | 8.8 | 0.4% | Nov 5, 2025 | Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta all... |
| CVE-2025-64108 | HIGH | 8.8 | 0.4% | Nov 4, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr... |
| CVE-2025-64107 | HIGH | 8.8 | 0.3% | Nov 4, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may ... |
| CVE-2025-64106 | HIGH | 8.8 | 0.3% | Nov 4, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor'... |
| CVE-2025-59595 | HIGH | 7.5 | 0.3% | Nov 4, 2025 | CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.... |
| CVE-2025-62507 | HIGH | 8.8 | 6.4% | Nov 4, 2025 | Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD... |
| CVE-2025-62369 | HIGH | 7.2 | 0.9% | Nov 4, 2025 | Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con... |
| CVE-2025-56230 | HIGH | 7.5 | 0.2% | Nov 4, 2025 | Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component. |
| CVE-2025-54526 | HIGH | 8.4 | 0.2% | Nov 4, 2025 | Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted pro... |
| CVE-2025-54496 | HIGH | 8.4 | 0.2% | Nov 4, 2025 | A maliciously crafted project file may cause a heap-based buffer overflow in Fuji Electric Monitouch V-SFT-6, which ma... |
| CVE-2025-32786 | HIGH | 7.5 | 6.0% | Nov 4, 2025 | The GLPI Inventory Plugin handles network discovery, inventory, software deployment, and data collection for GLPI agents... |
| CVE-2025-49494 | HIGH | 7.5 | 0.3% | Nov 4, 2025 | An issue was discovered in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 2100, 1280, 2200, 1330, 1380, ... |
| CVE-2025-23358 | HIGH | 8.2 | 0.2% | Nov 4, 2025 | NVIDIA NVApp for Windows contains a vulnerability in the installer, where a local attacker can cause a search path eleme... |
| CVE-2025-54334 | HIGH | 7.5 | 0.3% | Nov 4, 2025 | An issue was discovered in the NPU driver in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now