2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12433 | MEDIUM | 4.3 | 0.3% | Nov 10, 2025 | Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform out of b... |
| CVE-2025-12431 | MEDIUM | 6.5 | 0.2% | Nov 10, 2025 | Inappropriate implementation in Extensions in Google Chrome prior to 142.0.7444.59 allowed an attacker who convinced a u... |
| CVE-2025-47773 | MEDIUM | 6.1 | 0.2% | Nov 10, 2025 | Combodo iTop is a web based IT service management tool. Versions prior to 2.7.13 and 3.2.2 are vulnerable to cross-site ... |
| CVE-2025-43079 | MEDIUM | 6.3 | 0.1% | Nov 10, 2025 | The Qualys Cloud Agent included a bundled uninstall script (qagent_uninstall.sh), specific to Mac and Linux supported ve... |
| CVE-2025-63834 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | A stored cross-site scripting (XSS) vulnerability was discovered in Tenda AC18 v15.03.05.05_multi. The vulnerability exi... |
| CVE-2025-63710 | MEDIUM | 6.5 | 0.1% | Nov 10, 2025 | The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery ... |
| CVE-2025-63709 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text... |
| CVE-2025-41001 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of p... |
| CVE-2025-41107 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when ... |
| CVE-2025-12924 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the fu... |
| CVE-2025-12923 | MEDIUM | 4.9 | 0.5% | Nov 10, 2025 | A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownl... |
| CVE-2025-12920 | MEDIUM | 4.8 | 0.3% | Nov 9, 2025 | A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the fil... |
| CVE-2025-12918 | MEDIUM | 5.3 | 0.3% | Nov 9, 2025 | A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an u... |
| CVE-2025-12917 | MEDIUM | 4.3 | 0.5% | Nov 9, 2025 | A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file... |
| CVE-2025-12915 | MEDIUM | 6.4 | 0.4% | Nov 8, 2025 | A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init... |
| CVE-2025-12914 | MEDIUM | 4.7 | 0.2% | Nov 8, 2025 | A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /datab... |
| CVE-2025-12837 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Actio... |
| CVE-2025-12643 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay'... |
| CVE-2025-12092 | MEDIUM | 6.5 | 0.6% | Nov 8, 2025 | The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... |
| CVE-2025-11980 | MEDIUM | 4.9 | 0.3% | Nov 8, 2025 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all ... |
| CVE-2025-11448 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-12098 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive I... |
| CVE-2025-12621 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ... |
| CVE-2025-12498 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note c... |
| CVE-2025-7663 | MEDIUM | 6.5 | 0.2% | Nov 8, 2025 | The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now