2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12112 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The Insert Headers and Footers Code – HT Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ad... |
| CVE-2025-12064 | MEDIUM | 6.1 | 0.2% | Nov 8, 2025 | The WP2Social Auto Publish plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMessage in all v... |
| CVE-2025-12042 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Course Booking System plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability ... |
| CVE-2025-12000 | MEDIUM | 6.5 | 0.7% | Nov 8, 2025 | The WPFunnels plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in ... |
| CVE-2025-11972 | MEDIUM | 4.9 | 0.3% | Nov 8, 2025 | The Tag, Category, and Taxonomy Manager – AI Autotagger with OpenAI plugin for WordPress is vulnerable to SQL Injection ... |
| CVE-2025-11748 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The Groups plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, ... |
| CVE-2025-12583 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The Simple Downloads List plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-64495 | MEDIUM | 5.4 | 0.5% | Nov 8, 2025 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. In versions 0.6.34 an... |
| CVE-2025-64494 | MEDIUM | 4.6 | 0.2% | Nov 8, 2025 | Soft Serve is a self-hostable Git server for the command line. In versions prior to 0.10.0, there are several places whe... |
| CVE-2025-64493 | MEDIUM | 6.5 | 0.3% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.... |
| CVE-2025-64491 | MEDIUM | 6.1 | 0.2% | Nov 8, 2025 | SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 7.14.... |
| CVE-2025-64485 | MEDIUM | 5.3 | 0.3% | Nov 8, 2025 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 2.4.0 through 2.48.1... |
| CVE-2025-12911 | MEDIUM | 4.3 | 0.1% | Nov 8, 2025 | Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform... |
| CVE-2025-12910 | MEDIUM | 6.2 | 0.1% | Nov 8, 2025 | Inappropriate implementation in Passkeys in Google Chrome prior to 140.0.7339.80 allowed a local attacker to obtain pote... |
| CVE-2025-12909 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | Insufficient policy enforcement in Devtools in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to leak cr... |
| CVE-2025-12908 | MEDIUM | 5.4 | 0.2% | Nov 8, 2025 | Insufficient validation of untrusted input in Downloads in Google Chrome on Android prior to 140.0.7339.80 allowed a rem... |
| CVE-2025-12906 | MEDIUM | 5.4 | 0.1% | Nov 8, 2025 | Inappropriate implementation in Permissions in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform... |
| CVE-2025-12905 | MEDIUM | 5.4 | 0.1% | Nov 8, 2025 | Inappropriate implementation in Downloads in Google Chrome on Windows prior to 140.0.7339.80 allowed a remote attacker t... |
| CVE-2025-64437 | MEDIUM | 5 | 0.2% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. In versions before 1.5.3 and 1.6.1, the virt-handler doe... |
| CVE-2025-64436 | MEDIUM | 5.3 | 0.2% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. In 1.5.0 and earlier, the permissions granted to the vir... |
| CVE-2025-64435 | MEDIUM | 5.3 | 0.3% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.7.0-beta.0, a logic flaw in the virt-controll... |
| CVE-2025-64434 | MEDIUM | 6.3 | 0.2% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, due to the peer verification l... |
| CVE-2025-64433 | MEDIUM | 6.5 | 0.4% | Nov 7, 2025 | KubeVirt is a virtual machine management add-on for Kubernetes. Prior to 1.5.3 and 1.6.1, a vulnerability was discovered... |
| CVE-2025-63420 | MEDIUM | 4.1 | 0.2% | Nov 7, 2025 | CrushFTP11 before 11.3.7_57 is vulnerable to stored HTML injection in the CrushFTP Admin Panel (Reports / "Who Created F... |
| CVE-2025-12418 | MEDIUM | 5.6 | 0.1% | Nov 7, 2025 | Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2,... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now