2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12173 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-12078 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMess... |
| CVE-2025-11868 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in ... |
| CVE-2025-8404 | MEDIUM | 5.5 | 0.3% | Nov 18, 2025 | Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access t... |
| CVE-2025-11267 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_... |
| CVE-2025-11265 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta... |
| CVE-2025-7623 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a s... |
| CVE-2025-12524 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc... |
| CVE-2025-52578 | MEDIUM | 5.7 | 0.1% | Nov 18, 2025 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a soph... |
| CVE-2025-52457 | MEDIUM | 5.7 | 0.1% | Nov 18, 2025 | Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extr... |
| CVE-2025-7711 | MEDIUM | 5.4 | 0.2% | Nov 17, 2025 | The The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to arbitrary ... |
| CVE-2025-64766 | MEDIUM | 5.3 | 0.2% | Nov 17, 2025 | NixOS's Onlyoffice is a software suite that offers online and offline tools for document editing, collaboration, and man... |
| CVE-2025-36299 | MEDIUM | 4.3 | 0.2% | Nov 17, 2025 | IBM Planning Analytics Local 2.1.0 through 2.1.14 stores sensitive information in source code could be used in further a... |
| CVE-2025-64758 | MEDIUM | 4.8 | 0.2% | Nov 17, 2025 | @dependencytrack/frontend is a Single Page Application (SPA) used in Dependency-Track, an open source Component Analysis... |
| CVE-2025-64342 | MEDIUM | 6.9 | 0.3% | Nov 17, 2025 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. When the ESP32 is in advertising mode, if it re... |
| CVE-2025-55059 | MEDIUM | 6.1 | 0.1% | Nov 17, 2025 | CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-55056 | MEDIUM | 6.1 | 0.1% | Nov 17, 2025 | Multiple CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') |
| CVE-2025-63918 | MEDIUM | 6.2 | 0.3% | Nov 17, 2025 | PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attacker... |
| CVE-2025-13193 | MEDIUM | 5.5 | 0.1% | Nov 17, 2025 | A flaw was found in libvirt. External inactive snapshots for shut-down VMs are incorrectly created as world-readable, ma... |
| CVE-2025-64046 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | OpenRapid RapidCMS 1.3.1 is vulnerable to Cross Site Scripting (XSS) in /system/update-run.php. |
| CVE-2025-63708 | MEDIUM | 6.1 | 0.2% | Nov 17, 2025 | Cross-Site Scripting (XSS) vulnerability exists in SourceCodester AI Font Matcher (nid=18425, 2025-10-10) that allows re... |
| CVE-2025-40834 | MEDIUM | 6.8 | 0.2% | Nov 17, 2025 | A vulnerability has been identified in Mendix RichText (All versions >= V4.0.0 < V4.6.1). Affected widget does not prope... |
| CVE-2025-11681 | MEDIUM | 6.5 | 0.4% | Nov 17, 2025 | Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2... |
| CVE-2025-13275 | MEDIUM | 4.7 | 0.2% | Nov 17, 2025 | A security vulnerability has been detected in Iqbolshoh php-business-website up to 10677743a8dfc281f85291a27cf63a0bce043... |
| CVE-2025-13268 | MEDIUM | 6.3 | 0.2% | Nov 17, 2025 | A flaw has been found in Dromara dataCompare up to 1.0.1. The affected element is the function DbConfig of the file src/... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now