2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10567 | MEDIUM | 6.3 | 0.2% | Nov 5, 2025 | The FunnelKit WordPress plugin before 3.12.0.1 does not sanitize user input before echoing it back in some of its check... |
| CVE-2025-11162 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-12580 | MEDIUM | 6.1 | 0.2% | Nov 5, 2025 | The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in ... |
| CVE-2025-11835 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2025-8871 | MEDIUM | 5.6 | 0.2% | Nov 5, 2025 | The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... |
| CVE-2025-12582 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2025-62722 | MEDIUM | 5.4 | 0.2% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functio... |
| CVE-2025-59596 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addr... |
| CVE-2025-62721 | MEDIUM | 6.5 | 0.3% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints... |
| CVE-2025-62720 | MEDIUM | 6.5 | 0.3% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to expo... |
| CVE-2025-62719 | MEDIUM | 4.3 | 0.3% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function... |
| CVE-2025-62715 | MEDIUM | 5.4 | 0.2% | Nov 4, 2025 | ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Script... |
| CVE-2025-62520 | MEDIUM | 4.3 | 0.2% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-... |
| CVE-2025-55155 | MEDIUM | 5.4 | 0.1% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, when a user edits their pro... |
| CVE-2025-54335 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | An issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-afte... |
| CVE-2025-48884 | MEDIUM | 6.1 | 0.2% | Nov 4, 2025 | Galette is a membership management web application for non profit organizations. In versions 1.1.5.2 and below, Galette'... |
| CVE-2025-48076 | MEDIUM | 5.4 | 0.1% | Nov 4, 2025 | Galette is a membership management web application for non profit organizations. Versions 1.1.5.2 and below allow a user... |
| CVE-2025-27374 | MEDIUM | 5.3 | 0.3% | Nov 4, 2025 | An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 982... |
| CVE-2025-61431 | MEDIUM | 6.1 | 0.2% | Nov 4, 2025 | A reflected cross-site scripted (XSS) vulnerability in the /jsp/gsfr_feditorHTML.jsp endpoint of Zucchetti ZMaintenance ... |
| CVE-2025-54327 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | An issue was discovered in VTS in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1380, W920, W930, W... |
| CVE-2025-33176 | MEDIUM | 6.2 | 0.1% | Nov 4, 2025 | NVIDIA RunAI for all platforms contains a vulnerability where a user could cause an improper restriction of communicatio... |
| CVE-2025-64322 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Agentforce Vibes Extension allows Mani... |
| CVE-2025-64321 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Ma... |
| CVE-2025-64320 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Co... |
| CVE-2025-64319 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | Incorrect Permission Assignment for Critical Resource vulnerability in Salesforce Mulesoft Anypoint Code Builder allows ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now