2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12963 | CRITICAL | 9.8 | 0.3% | Dec 12, 2025 | The LazyTasks – Project & Task Management with Collaboration, Kanban and Gantt Chart plugin for WordPress is vulnerable ... |
| CVE-2025-12883 | MEDIUM | 5.3 | 0.3% | Dec 12, 2025 | The Campay Woocommerce Payment Gateway plugin for WordPress is vulnerable to Unauthenticated Payment Bypass in all versi... |
| CVE-2025-12834 | MEDIUM | 6.1 | 0.2% | Dec 12, 2025 | The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via... |
| CVE-2025-12830 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Better Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider widget in a... |
| CVE-2025-12824 | HIGH | 8.8 | 0.7% | Dec 12, 2025 | The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, ... |
| CVE-2025-12783 | MEDIUM | 4.3 | 0.2% | Dec 12, 2025 | The Premmerce Brands for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2025-12650 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The Simple post listing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_name' parameter... |
| CVE-2025-13886 | HIGH | 7.5 | 0.5% | Dec 12, 2025 | The LT Unleashed plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.1 ... |
| CVE-2025-13839 | MEDIUM | 6.4 | 0.2% | Dec 12, 2025 | The LJUsers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'name' parameter of the 'ljuser' s... |
| CVE-2025-13670 | MEDIUM | 6.7 | 0.1% | Dec 12, 2025 | The High Level Synthesis Compiler i++ command for Windows is vulnerable to a DLL planting vulnerability |
| CVE-2025-13669 | MEDIUM | 6.7 | 0.1% | Dec 12, 2025 | Uncontrolled Search Path Element vulnerability in Altera High Level Synthesis Compiler on Windows allows Search Order Hi... |
| CVE-2025-13665 | MEDIUM | 6.7 | 0.1% | Dec 12, 2025 | The System Console Utility for Windows is vulnerable to a DLL planting vulnerability |
| CVE-2025-13053 | LOW | 3.7 | 0.1% | Dec 12, 2025 | When a user configures the NAS to retrieve UPS status or control the UPS, a non-enforced TLS certificate verification ca... |
| CVE-2025-13052 | MEDIUM | 5.9 | 0.2% | Dec 12, 2025 | When the user set the Notification's sender to send emails to the SMTP server via msmtp, an improper validated TLS/SSL c... |
| CVE-2025-10451 | HIGH | 8.2 | 0.1% | Dec 12, 2025 | Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption. |
| CVE-2025-67779 | HIGH | 7.5 | 18.9% | Dec 12, 2025 | It was found that the fix addressing CVE-2025-55184 in React Server Components was incomplete and does not prevent a den... |
| CVE-2025-67780 | MEDIUM | 4.2 | 0.1% | Dec 11, 2025 | SpaceX Starlink Dish devices with firmware 2024.12.04.mr46620 (e.g., on Mini1_prod2) allow administrative actions via un... |
| CVE-2025-66452 | MEDIUM | 6.1 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing... |
| CVE-2025-66451 | MEDIUM | 6.5 | 0.3% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests... |
| CVE-2025-66450 | MEDIUM | 5.4 | 0.2% | Dec 11, 2025 | LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the ic... |
| CVE-2025-66446 | HIGH | 7.5 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow... |
| CVE-2025-66419 | CRITICAL | 10 | 0.3% | Dec 11, 2025 | MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to ... |
| CVE-2025-64721 | CRITICAL | 10 | 0.6% | Dec 11, 2025 | Sandboxie is a sandbox-based isolation software for 32-bit and 64-bit Windows NT-based operating systems. In versions 1.... |
| CVE-2025-34506 | HIGH | 8.8 | 0.8% | Dec 11, 2025 | WBCE CMS version 1.6.3 and prior contains an authenticated remote code execution vulnerability that allows administrator... |
| CVE-2025-34504 | MEDIUM | 6.1 | 0.3% | Dec 11, 2025 | KodExplorer 4.52 contains an open redirect vulnerability in the user login page that allows attackers to manipulate the ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now