2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12760 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.T... |
| CVE-2025-9977 | MEDIUM | 5.3 | 2.1% | Nov 18, 2025 | Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not saniti... |
| CVE-2025-64996 | MEDIUM | 4.4 | 0.1% | Nov 18, 2025 | In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates worl... |
| CVE-2025-63604 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code executi... |
| CVE-2025-63603 | MEDIUM | 6.5 | 0.8% | Nov 18, 2025 | A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) ... |
| CVE-2025-58122 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notifi... |
| CVE-2025-58121 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.... |
| CVE-2025-8084 | MEDIUM | 6.8 | 0.4% | Nov 18, 2025 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.... |
| CVE-2025-63892 | MEDIUM | 6.8 | 0.3% | Nov 18, 2025 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_c... |
| CVE-2025-63883 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client... |
| CVE-2025-59117 | MEDIUM | 4.8 | 0.2% | Nov 18, 2025 | Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu... |
| CVE-2025-59116 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow ... |
| CVE-2025-59115 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation... |
| CVE-2025-59114 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft spec... |
| CVE-2025-59112 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft specia... |
| CVE-2025-59111 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques... |
| CVE-2025-59110 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechani... |
| CVE-2025-55179 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Incomplete validation of rich response messages in WhatsApp for iOS prior to v2.25.23.73, WhatsApp Business for iOS v2.2... |
| CVE-2025-13349 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | A vulnerability has been found in SourceCodester Student Grades Management System 1.0. This issue affects some unknown p... |
| CVE-2025-12545 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | The Pixel Manager for WooCommerce – Track Conversions and Analytics, Google Ads, TikTok and more plugin for WordPress is... |
| CVE-2025-12376 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The Icon List Block – Add Icon-Based Lists with Custom Styles plugin for WordPress is vulnerable to Server-Side Request ... |
| CVE-2025-10158 | MEDIUM | 4.3 | 0.3% | Nov 18, 2025 | A malicious client acting as the receiver of an rsync file transfer can trigger an out of bounds read of a heap based bu... |
| CVE-2025-41350 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store... |
| CVE-2025-41349 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | Stored Cross-site Scripting (XSS)vylnerability type in WinPlus v24.11.27 byInformática del Este that consist of an store... |
| CVE-2025-13343 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | A security flaw has been discovered in SourceCodester Interview Management System 1.0. Affected is an unknown function o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now