2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52186 | MEDIUM | 6.5 | 0.3% | Nov 13, 2025 | Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery ... |
| CVE-2025-13120 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | A vulnerability has been found in mruby up to 3.4.0. This vulnerability affects the function sort_cmp of the file src/ar... |
| CVE-2025-64738 | MEDIUM | 5.5 | 0.1% | Nov 13, 2025 | External control of file name or path in Zoom Workplace for macOS before version 6.5.10 may allow an authenticated user ... |
| CVE-2025-62482 | MEDIUM | 6.1 | 0.2% | Nov 13, 2025 | Cross-site scripting in Zoom Workplace for Windows before version 6.5.10 may allow an unauthenticated user to impact int... |
| CVE-2025-30669 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Improper certificate validation in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of inf... |
| CVE-2025-30662 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Symlink following in the installer for the Zoom Workplace VDI Plugin macOS Universal installer before version 6.3.14, 6.... |
| CVE-2025-13119 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | A flaw has been found in Fabian Ros/SourceCodester Simple E-Banking System 1.0. This affects an unknown part. This manip... |
| CVE-2025-13118 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | A vulnerability was detected in macrozheng mall-swarm up to 1.0.3. Affected by this issue is the function paySuccess of ... |
| CVE-2025-13117 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | A security vulnerability has been detected in macrozheng mall-swarm and mall up to 1.0.3. Affected by this vulnerability... |
| CVE-2025-41069 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in DeporSite of T-INNOVA. This vulnerability allows an attacker to... |
| CVE-2025-13116 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | A weakness has been identified in macrozheng mall-swarm and mall up to 1.0.3. Affected is the function cancelUserOrder o... |
| CVE-2025-13115 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | A security flaw has been discovered in macrozheng mall-swarm and mall up to 1.0.3. This impacts the function detail of t... |
| CVE-2025-13114 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | A vulnerability was identified in macrozheng mall-swarm up to 1.0.3. This affects the function updateAttr of the file /c... |
| CVE-2025-40681 | MEDIUM | 5.1 | 0.3% | Nov 13, 2025 | Cross-site Scripting (XSS) vulnerability reflected in xCally's Omnichannel v3.30.1. This vulnerability allowsan attacker... |
| CVE-2025-12818 | MEDIUM | 5.9 | 0.3% | Nov 13, 2025 | Integer wraparound in multiple PostgreSQL libpq client library functions allows an application input provider or network... |
| CVE-2025-12377 | MEDIUM | 4.3 | 0.3% | Nov 13, 2025 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-7704 | MEDIUM | 5.4 | 0.2% | Nov 13, 2025 | Supermicro BMC Insyde SMASH shell program has a stacked-based overflow vulnerability |
| CVE-2025-64384 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in jetmonsters JetFormBuilder jetformbuilder allows Exploiting Incorrectly Configure... |
| CVE-2025-64383 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Qode Qi Blocks qi-... |
| CVE-2025-64382 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in WebToffee Order Export & Order Import for WooCommerce order-import-export-for-woo... |
| CVE-2025-64381 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop Booking ... |
| CVE-2025-64380 | MEDIUM | 6.5 | 0.1% | Nov 13, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pluggabl Booster f... |
| CVE-2025-64379 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in Pluggabl Booster for WooCommerce woocommerce-jetpack allows Exploiting Incorrectl... |
| CVE-2025-64370 | MEDIUM | 5.3 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in YOP YOP Poll yop-poll allows Exploiting Incorrectly Configured Access Control Sec... |
| CVE-2025-64369 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | Missing Authorization vulnerability in codepeople Contact Form Email contact-form-to-email allows Exploiting Incorrectly... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now