2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12366 | MEDIUM | 4.3 | 0.2% | Nov 13, 2025 | The Page Builder: Pagelayer – Drag and Drop website builder plugin for WordPress is vulnerable to Insecure Direct Object... |
| CVE-2025-12089 | MEDIUM | 6.5 | 0.5% | Nov 13, 2025 | The Data Tables Generator by Supsystic plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient... |
| CVE-2025-64716 | MEDIUM | 5.1 | 0.5% | Nov 13, 2025 | Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap... |
| CVE-2025-64711 | MEDIUM | 5.4 | 0.1% | Nov 13, 2025 | PrivateBin is an online pastebin where the server has zero knowledge of pasted data. Starting in version 1.7.7 and prior... |
| CVE-2025-64710 | MEDIUM | 5.3 | 0.3% | Nov 13, 2025 | Bitplatform Boilerplate is a Visual studio and .NET project template. Versions prior to 9.11.3 are affected by a cross-s... |
| CVE-2025-64707 | MEDIUM | 5.4 | 0.1% | Nov 12, 2025 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve... |
| CVE-2025-64705 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to ve... |
| CVE-2025-64517 | MEDIUM | 4.4 | 0.1% | Nov 12, 2025 | sudo-rs is a memory safe implementation of sudo and su written in Rust. With `Defaults targetpw` (or `Defaults rootpw`) ... |
| CVE-2025-64482 | MEDIUM | 4.6 | 0.1% | Nov 12, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Editio... |
| CVE-2025-64429 | MEDIUM | 6.5 | 0.1% | Nov 12, 2025 | DuckDB is a SQL database management system. DuckDB implemented block-based encryption of DB on the filesystem starting w... |
| CVE-2025-63645 | MEDIUM | 5.4 | 0.2% | Nov 12, 2025 | A stored cross-site scripting (XSS) vulnerability exists in pH7Software pH7-Social-Dating-CMS 17.9.1 in the application'... |
| CVE-2025-33119 | MEDIUM | 6.5 | 0.2% | Nov 12, 2025 | IBM QRadar SIEM 7.5 through 7.5.0 UP14 stores user credentials in configuration files in source control which can be rea... |
| CVE-2025-64186 | MEDIUM | 6.5 | 0.1% | Nov 12, 2025 | Evervault is a payment security solution. A vulnerability was identified in the `evervault-go` SDK’s attestation verific... |
| CVE-2025-36223 | MEDIUM | 6.1 | 0.1% | Nov 12, 2025 | IBM OpenPages 9.0 and 9.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST hea... |
| CVE-2025-8421 | MEDIUM | 6.6 | 0.1% | Nov 12, 2025 | An improper default permission vulnerability was reported in Lenovo Dock Manager that, under certain conditions during i... |
| CVE-2025-64117 | MEDIUM | 4.6 | 0.1% | Nov 12, 2025 | Tuleap is an Open Source Suite to improve management of software developments and collaboration. Tuleap Community Editio... |
| CVE-2025-27368 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | IBM OpenPages 9.0 and 9.1 is vulnerable to information disclosure of sensitive information due to a weaker than expected... |
| CVE-2025-13058 | MEDIUM | 5.4 | 0.2% | Nov 12, 2025 | A security flaw has been discovered in soerennb eXtplorer up to 2.1.15. The affected element is an unknown function of t... |
| CVE-2025-12047 | MEDIUM | 6 | 0.2% | Nov 12, 2025 | A vulnerability was reported in the Lenovo Scanner pro application during an internal security assessment that, under ce... |
| CVE-2025-63927 | MEDIUM | 4 | 0.2% | Nov 12, 2025 | A heap-use-after-free vulnerability exists in airpig2011 IEC104 thru Commit be6d841 (2019-07-08). During multi-threaded ... |
| CVE-2025-60646 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | A stored cross-site scripting (XSS) in the Business Line Management module of Xxl-api v1.3.0 attackers to execute arbitr... |
| CVE-2025-60645 | MEDIUM | 6.5 | 0.1% | Nov 12, 2025 | A Cross-Site Request Forgery (CSRF) in xxl-api v1.3.0 allows attackers to arbitrarily add users to the management module... |
| CVE-2025-25236 | MEDIUM | 5.3 | 0.2% | Nov 12, 2025 | Omnissa Workspace ONE UEM contains an observable response discrepancy vulnerability. A malicious actor may be able to en... |
| CVE-2025-20378 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | In Splunk Enterprise versions below 10.0.1, 9.4.5, 9.3.7, 9.2.9, and Splunk Cloud Platform versions below 10.0.2503.5, 9... |
| CVE-2025-63419 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | Cross Site Scripting (XSS) vulnerability in CrushFTP 11.3.6_48. The Web-Based Server has a feature where users can share... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now