2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7623 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a s... |
| CVE-2025-12524 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc... |
| CVE-2025-52578 | MEDIUM | 5.7 | 0.1% | Nov 18, 2025 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a soph... |
| CVE-2025-52457 | MEDIUM | 5.7 | 0.1% | Nov 18, 2025 | Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extr... |
| CVE-2025-7711 | MEDIUM | 5.4 | 0.2% | Nov 17, 2025 | The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary ... |
| CVE-2025-64766 | MEDIUM | 5.3 | 0.2% | Nov 17, 2025 | NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and man... |
| CVE-2025-36299 | MEDIUM | 4.3 | 0.2% | Nov 17, 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further a... |
| CVE-2025-64758 | MEDIUM | 4.8 | 0.2% | Nov 17, 2025 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis... |
| CVE-2025-64342 | MEDIUM | 6.9 | 0.3% | Nov 17, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it re... |
| CVE-2025-55059 | MEDIUM | 6.1 | 0.1% | Nov 17, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55056 | MEDIUM | 6.1 | 0.1% | Nov 17, 2025 | Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-63918 | MEDIUM | 6.2 | 0.3% | Nov 17, 2025 | PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attacker... |
| CVE-2025-13193 | MEDIUM | 5.5 | 0.1% | Nov 17, 2025 | A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, ma... |
| CVE-2025-64046 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php. |
| CVE-2025-63708 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows re... |
| CVE-2025-40834 | MEDIUM | 6.8 | 0.2% | Nov 17, 2025 | A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not prope... |
| CVE-2025-11681 | MEDIUM | 6.5 | 0.4% | Nov 17, 2025 | Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2... |
| CVE-2025-13275 | MEDIUM | 4.7 | 0.2% | Nov 17, 2025 | A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043... |
| CVE-2025-13268 | MEDIUM | 6.3 | 0.2% | Nov 17, 2025 | A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/... |
| CVE-2025-13164 | MEDIUM | 6.9 | 0.3% | Nov 17, 2025 | EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a... |
| CVE-2025-13163 | MEDIUM | 6.9 | 0.3% | Nov 17, 2025 | EasyFlow GP developed by Digiwin has an Insufficiently Protected Credentials vulnerability, allowing privileged remote a... |
| CVE-2025-60022 | MEDIUM | 4.8 | 0.1% | Nov 17, 2025 | Improper certificate validation vulnerability exists in 'デジラアプリ' App for iOS prior to ver.80.10.00. If this vulnerabilit... |
| CVE-2025-13266 | MEDIUM | 5.5 | 0.5% | Nov 17, 2025 | A security vulnerability has been detected in wwwlike vlife up to 2.0.1. This issue affects the function create of the f... |
| CVE-2025-13261 | MEDIUM | 5.3 | 0.6% | Nov 17, 2025 | A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the fil... |
| CVE-2025-13249 | MEDIUM | 6.3 | 0.2% | Nov 16, 2025 | A security vulnerability has been detected in Jiusi OA up to 20251102. This affects an unknown function of the file /Off... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now