2025 CVE Vulnerabilities
45,145 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-59491 | MEDIUM | 6.1 | 0.2% | Nov 12, 2025 | Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields. |
| CVE-2025-59089 | MEDIUM | 5.9 | 0.5% | Nov 12, 2025 | If an attacker causes kdcproxy to connect to an attacker-controlled KDC server (e.g. through server-side request forgery... |
| CVE-2025-52331 | MEDIUM | 6.1 | 0.3% | Nov 12, 2025 | Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to... |
| CVE-2025-9316 | MEDIUM | 6.9 | 36.7% | Nov 12, 2025 | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. |
| CVE-2025-11566 | MEDIUM | 6.9 | 0.5% | Nov 12, 2025 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker on ... |
| CVE-2025-62876 | MEDIUM | 5.3 | 0.1% | Nov 12, 2025 | A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to ... |
| CVE-2025-40164 | MEDIUM | 5.5 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: usbnet: Fix using smp_processor_id() in preemptible... |
| CVE-2025-11454 | MEDIUM | 6.5 | 0.3% | Nov 12, 2025 | The Specific Content For Mobile – Customize the mobile version without redirections plugin for WordPress is vulnerable t... |
| CVE-2025-64407 | MEDIUM | 5.3 | 0.4% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-61623 | MEDIUM | 6.5 | 0.7% | Nov 12, 2025 | Reflected cross-site scripting vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.03. Users ... |
| CVE-2025-37734 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | Origin Validation Error in Kibana can lead to Server-Side Request Forgery via a forged Origin HTTP header processed by t... |
| CVE-2025-64406 | MEDIUM | 4.3 | 0.4% | Nov 12, 2025 | An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash t... |
| CVE-2025-64402 | MEDIUM | 6.5 | 0.5% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-12732 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sen... |
| CVE-2025-12872 | MEDIUM | 5.4 | 0.2% | Nov 12, 2025 | The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote ... |
| CVE-2025-12869 | MEDIUM | 4.8 | 0.2% | Nov 12, 2025 | The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administr... |
| CVE-2025-12113 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unaut... |
| CVE-2025-12018 | MEDIUM | 4.4 | 0.2% | Nov 12, 2025 | The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2025-12901 | MEDIUM | 4.3 | 0.1% | Nov 12, 2025 | The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-12833 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2025-12087 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i... |
| CVE-2025-54983 | MEDIUM | 5.2 | 0.1% | Nov 12, 2025 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under sp... |
| CVE-2025-43205 | MEDIUM | 4 | 0.1% | Nov 12, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18... |
| CVE-2025-40760 | MEDIUM | 6.8 | 0.1% | Nov 11, 2025 | A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly ... |
| CVE-2025-12748 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files w... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now