2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-65020 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Rallly is an open-source scheduling and collaboration tool. Prior to version 4.5.4, an Insecure Direct Object Reference ... |
| CVE-2025-65019 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.9, when using Astro's Cloudflare adapter (@astrojs/cloudflare) with outp... |
| CVE-2025-64765 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.8, a mismatch exists between how Astro normalizes request paths for rout... |
| CVE-2025-64764 | MEDIUM | 5.4 | 0.4% | Nov 19, 2025 | Astro is a web framework. Prior to version 5.15.8, a reflected XSS vulnerability is present when the server islands feat... |
| CVE-2025-64708 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, in previous authentik versions,... |
| CVE-2025-64521 | MEDIUM | 4.8 | 0.2% | Nov 19, 2025 | authentik is an open-source Identity Provider. Prior to versions 2025.8.5 and 2025.10.2, when authenticating with client... |
| CVE-2025-34336 | MEDIUM | 6.9 | 0.5% | Nov 19, 2025 | eGovFramework/egovframe-common-components versions up to and including 4.3.1 contain an unauthenticated file upload vuln... |
| CVE-2025-34330 | MEDIUM | 5.3 | 0.4% | Nov 19, 2025 | AudioCodes Fax Server and Auto-Attendant IVR appliances versions up to and including 2.6.23 include a web administration... |
| CVE-2025-12766 | MEDIUM | 5 | 0.2% | Nov 19, 2025 | An Insecure Direct Object Reference (IDOR) vulnerability in the Management Console of BlackBerry® AtHoc® (OnPrem) versio... |
| CVE-2025-12743 | MEDIUM | 6 | 0.2% | Nov 19, 2025 | The Looker endpoint for generating new projects from database connections allows users to specify "looker" as a connecti... |
| CVE-2025-63879 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | A reflected cross-site scripted (XSS) vulnerability in the /ecommerce/products.php component of E-commerce Project v1.0 ... |
| CVE-2025-63878 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Github Restaurant Website Restoran v1.0 was discovered to contain a SQL injection vulnerability via the Contact Form pag... |
| CVE-2025-13397 | MEDIUM | 5.5 | 0.1% | Nov 19, 2025 | A security vulnerability has been detected in mrubyc up to 3.4. This impacts the function mrbc_raw_realloc of the file s... |
| CVE-2025-63243 | MEDIUM | 4.6 | 0.2% | Nov 19, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the password change functionality of Pixeon WebLaudos 25.... |
| CVE-2025-11963 | MEDIUM | 5.4 | 0.1% | Nov 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saysis Comp... |
| CVE-2025-0421 | MEDIUM | 4.7 | 0.2% | Nov 19, 2025 | Improper Restriction of Rendered UI Layers or Frames vulnerability in Shopside Software Technologies Inc. Shopside allow... |
| CVE-2025-64408 | MEDIUM | 6.3 | 9.4% | Nov 19, 2025 | Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controlla... |
| CVE-2025-58412 | MEDIUM | 6.1 | 0.1% | Nov 19, 2025 | A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0... |
| CVE-2025-11446 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know... |
| CVE-2025-13206 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2025-13085 | MEDIUM | 4.3 | 0.2% | Nov 19, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta... |
| CVE-2025-12535 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and includi... |
| CVE-2025-13054 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2025-12878 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-12842 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sendi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now