2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12833 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2025-12087 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i... |
| CVE-2025-54983 | MEDIUM | 5.2 | 0.1% | Nov 12, 2025 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under sp... |
| CVE-2025-43205 | MEDIUM | 4 | 0.1% | Nov 12, 2025 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 18.4 and iPadOS 18... |
| CVE-2025-40760 | MEDIUM | 6.8 | 0.1% | Nov 11, 2025 | A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly ... |
| CVE-2025-12748 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | A flaw was discovered in libvirt in the XML file processing. More specifically, the parsing of user provided XML files w... |
| CVE-2025-61845 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61844 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61843 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61842 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by a Use After Free vulnerability that could lead to memory expos... |
| CVE-2025-61841 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-61840 | MEDIUM | 5.5 | 0.2% | Nov 11, 2025 | Format Plugins versions 1.1.1 and earlier are affected by an Out-of-bounds Read vulnerability that could lead to memory ... |
| CVE-2025-62453 | MEDIUM | 5 | 0.4% | Nov 11, 2025 | Improper validation of generative ai output in GitHub Copilot and Visual Studio Code allows an authorized attacker to by... |
| CVE-2025-62449 | MEDIUM | 6.8 | 0.4% | Nov 11, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in Visual Studio Code CoPilot Chat Extens... |
| CVE-2025-62214 | MEDIUM | 6.7 | 1.0% | Nov 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Visual Studio allows an authorize... |
| CVE-2025-62209 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in... |
| CVE-2025-62208 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Insertion of sensitive information into log file in Windows License Manager allows an authorized attacker to disclose in... |
| CVE-2025-62206 | MEDIUM | 6.5 | 0.9% | Nov 11, 2025 | Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an unauthorize... |
| CVE-2025-60728 | MEDIUM | 4.3 | 0.7% | Nov 11, 2025 | Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a n... |
| CVE-2025-60723 | MEDIUM | 6.3 | 0.8% | Nov 11, 2025 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DirectX allows an... |
| CVE-2025-60722 | MEDIUM | 6.5 | 0.8% | Nov 11, 2025 | Improper limitation of a pathname to a restricted directory ('path traversal') in OneDrive for Android allows an authori... |
| CVE-2025-60708 | MEDIUM | 6.5 | 0.4% | Nov 11, 2025 | Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. |
| CVE-2025-60706 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | Out-of-bounds read in Windows Hyper-V allows an authorized attacker to disclose information locally. |
| CVE-2025-59513 | MEDIUM | 5.5 | 0.4% | Nov 11, 2025 | Out-of-bounds read in Windows Bluetooth RFCOM Protocol Driver allows an authorized attacker to disclose information loca... |
| CVE-2025-59510 | MEDIUM | 5.5 | 0.5% | Nov 11, 2025 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allow... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now