2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12822 | MEDIUM | 4.3 | 0.2% | Nov 19, 2025 | The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-12814 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect ... |
| CVE-2025-12751 | MEDIUM | 4.3 | 0.2% | Nov 19, 2025 | The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-12710 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shor... |
| CVE-2025-12359 | MEDIUM | 5.4 | 0.2% | Nov 19, 2025 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t... |
| CVE-2025-12174 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-12349 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth... |
| CVE-2025-6251 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi... |
| CVE-2025-12777 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... |
| CVE-2025-12770 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu... |
| CVE-2025-12427 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ... |
| CVE-2025-13225 | MEDIUM | 6 | 0.1% | Nov 19, 2025 | Tanium addressed an arbitrary file deletion vulnerability in TanOS. |
| CVE-2025-65093 | MEDIUM | 5.5 | 3.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based ... |
| CVE-2025-65013 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cros... |
| CVE-2025-65012 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Kirby is an open-source content management system. From versions 5.0.0 to 5.1.3, attackers could change the title of any... |
| CVE-2025-64515 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | Open Forms allows users create and publish smart forms. Prior to versions 3.2.7 and 3.3.3, forms where the prefill data ... |
| CVE-2025-54990 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | XWiki AdminTools integrates administrative tools for managing a running XWiki instance. Prior to version 1.1, users with... |
| CVE-2025-63229 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The Mozart FM Transmitter web management interface on version WEBMOZZI-00287, contains a reflected Cross-Site Scripting ... |
| CVE-2025-63226 | MEDIUM | 5.7 | 0.2% | Nov 18, 2025 | The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking... |
| CVE-2025-63749 | MEDIUM | 6.5 | 0.9% | Nov 18, 2025 | pnetlab 5.3.11 is vulnerable to Command Injection via the qemu_options parameter. |
| CVE-2025-63693 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping fo... |
| CVE-2025-61664 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability in the GRUB2 bootloader has been identified in the normal module. This flaw, a memory Use After Free iss... |
| CVE-2025-61663 | MEDIUM | 4.9 | 0.1% | Nov 18, 2025 | A vulnerability has been identified in the GRUB2 bootloader's normal command that poses an immediate Denial of Service (... |
| CVE-2025-61661 | MEDIUM | 4.8 | 0.2% | Nov 18, 2025 | A vulnerability has been identified in the GRUB (Grand Unified Bootloader) component. This flaw occurs because the bootl... |
| CVE-2025-56499 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | Incorrect access control in mihomo v1.19.11 allows authenticated attackers with low-level privileges to read arbitrary f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now