2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41104 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41103 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41102 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41101 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-11960 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Softw... |
| CVE-2025-7633 | MEDIUM | 6.1 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-7632 | MEDIUM | 5.4 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-7430 | MEDIUM | 5.4 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-12953 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una... |
| CVE-2025-12788 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment veri... |
| CVE-2025-12787 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking... |
| CVE-2025-9524 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usabilit... |
| CVE-2025-9055 | MEDIUM | 6.4 | 0.1% | Nov 11, 2025 | The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain L... |
| CVE-2025-7429 | MEDIUM | 5.4 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-5317 | MEDIUM | 5.5 | 0.1% | Nov 11, 2025 | An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 a... |
| CVE-2025-8108 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privileg... |
| CVE-2025-6779 | MEDIUM | 6.7 | 1.0% | Nov 11, 2025 | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privile... |
| CVE-2025-6571 | MEDIUM | 6 | 0.1% | Nov 11, 2025 | A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it. |
| CVE-2025-6298 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escala... |
| CVE-2025-5718 | MEDIUM | 6.8 | 0.3% | Nov 11, 2025 | The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be... |
| CVE-2025-5454 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote... |
| CVE-2025-5452 | MEDIUM | 6.6 | 0.3% | Nov 11, 2025 | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat... |
| CVE-2025-4645 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln... |
| CVE-2025-11237 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option va... |
| CVE-2025-12880 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now