2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13352 | LOW | 3 | 0.1% | Dec 17, 2025 | Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identit... |
| CVE-2025-67895 | CRITICAL | 9.8 | 0.8% | Dec 17, 2025 | Edge3 Worker RPC RCE on Airflow 2. This issue affects Apache Airflow Providers Edge3: before 2.0.0 - and only if you in... |
| CVE-2025-14095 | MEDIUM | 6.8 | 0.1% | Dec 17, 2025 | A "Privilege boundary violation" vulnerability is identified affecting multiple Radiometer Products. Exploitation of thi... |
| CVE-2025-14101 | HIGH | 7.1 | 0.2% | Dec 17, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in GG Soft Software Services Inc. PaperWork allows Exploi... |
| CVE-2025-14347 | MEDIUM | 6.3 | 0.2% | Dec 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-14399 | MEDIUM | 4.3 | 0.1% | Dec 17, 2025 | The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery i... |
| CVE-2025-12496 | MEDIUM | 4.9 | 0.6% | Dec 17, 2025 | The Zephyr Project Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and includin... |
| CVE-2025-14817 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | The component com.transsion.tranfacmode.entrance.main.MainActivity in com.transsion.tranfacmode has no permission contro... |
| CVE-2025-14061 | MEDIUM | 5.3 | 0.2% | Dec 17, 2025 | The Cookie Banner, Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) : WP Cookie C... |
| CVE-2025-13750 | MEDIUM | 4.3 | 0.2% | Dec 17, 2025 | The Converter for Media – Optimize images | Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized modif... |
| CVE-2025-11924 | HIGH | 7.5 | 0.4% | Dec 17, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Insecure Direct Obj... |
| CVE-2025-14154 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vu... |
| CVE-2025-64700 | MEDIUM | 5.1 | 0.1% | Dec 17, 2025 | Cross-site request forgery vulnerability exists in GROWI v7.3.3 and earlier. If a user views a malicious page while logg... |
| CVE-2025-59374 | CRITICAL | 9.8 | 1.1% | Dec 17, 2025 | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modificat... |
| CVE-2025-14385 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter in all ve... |
| CVE-2025-13880 | MEDIUM | 6.5 | 0.2% | Dec 17, 2025 | The WP Social Ninja – Embed Social Feeds, Customer Reviews, Chat Widgets (Google Reviews, YouTube Feed, Photo Feeds, and... |
| CVE-2025-13861 | MEDIUM | 6.1 | 0.2% | Dec 17, 2025 | The HTML Forms – Simple WordPress Forms Plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scriptin... |
| CVE-2025-11901 | HIGH | 7 | 0.2% | Dec 17, 2025 | An uncontrolled resource consumption vulnerability affects certain ASUS motherboards using Intel B460, B560, B660, B760... |
| CVE-2025-11775 | MEDIUM | 4.8 | 0.1% | Dec 17, 2025 | An out-of-bounds read vulnerability has been identified in the asComSvc service. This vulnerability can be triggered by ... |
| CVE-2025-14305 | HIGH | 8.5 | 0.1% | Dec 17, 2025 | ListCheck.exe developed by Acer has a Local Privilege Escalation vulnerability. Authenticated local attackers can replac... |
| CVE-2025-14304 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by ASRock and its subsidiaries, ASRockRack and ASRockInd. has a Protection Mechanis... |
| CVE-2025-13977 | MEDIUM | 6.4 | 0.3% | Dec 17, 2025 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2025-14303 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by MSI has a Protection Mechanism Failure vulnerability. Because IOMMU was not prop... |
| CVE-2025-14302 | HIGH | 7 | 0.3% | Dec 17, 2025 | Certain motherboard models developed by GIGABYTE has a Protection Mechanism Failure vulnerability. Because IOMMU was not... |
| CVE-2025-14801 | MEDIUM | 4.8 | 0.2% | Dec 17, 2025 | A security vulnerability has been detected in xiweicheng TMS up to 2.28.0. This affects the function createComment of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now