2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34399 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesCc param... |
| CVE-2025-34398 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the AddressesBcc para... |
| CVE-2025-34397 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain a reflected cross-site scripting (XSS) vulnerability in the Message parameter... |
| CVE-2025-34396 | HIGH | 7.3 | 0.2% | Dec 9, 2025 | MailEnable versions prior to 10.54 contain an unsafe DLL loading vulnerability that can lead to local arbitrary code exe... |
| CVE-2025-33214 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | NVIDIA NVTabular for Linux contains a vulnerability in the Workflow component, where a user could cause a deserializatio... |
| CVE-2025-33213 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a d... |
| CVE-2025-13924 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | The Advanced Product Fields (Product Addons) for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Fo... |
| CVE-2025-65289 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router... |
| CVE-2025-65288 | MEDIUM | 6.5 | 0.4% | Dec 9, 2025 | A buffer overflow in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) occurs when the device accepts and sto... |
| CVE-2025-63742 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | SQL Injection vulnerability in function setwxqyAction in file webmain/task/api/loginAction.php in Xinhu Rainrock RockOA ... |
| CVE-2025-63740 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | SQL Injection vulnerability in function getselectdataAjax in file inputAction.php in Xinhu Rainrock RockOA 2.7.0 allowin... |
| CVE-2025-63739 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | An issue was discovered in function phpinisaveAction in file webmain/system/cogini/coginiAction.php in Xinhu Rainrock Ro... |
| CVE-2025-63738 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | An issue was discovered in file index.php in Xinhu Rainrock RockOA 2.7.0 allowing attackers to gain sensitive informatio... |
| CVE-2025-63737 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | Cross-site scripting (XSS) vulnerability in function urltestAction in file cliAction.php in Xinhu Rainrock RockOA 2.7.0 ... |
| CVE-2025-56704 | HIGH | 8.8 | 0.7% | Dec 9, 2025 | LeptonCMS version 7.3.0 contains an arbitrary file upload vulnerability, which is caused by the lack of proper validatio... |
| CVE-2025-12946 | HIGH | 7.5 | 0.3% | Dec 9, 2025 | A vulnerability in the speedtest feature of affected NETGEAR Nighthawk routers, caused by improper input validation, can... |
| CVE-2025-12945 | HIGH | 7.2 | 1.6% | Dec 9, 2025 | A vulnerability in NETGEAR Nighthawk R7000P routers lets an authenticated admin execute OS command injections due to imp... |
| CVE-2025-12941 | MEDIUM | 5.7 | 0.2% | Dec 9, 2025 | Denial of Service Vulnerability in NETGEAR C6220 and C6230 (DOCSIS® 3.0 Two-in-one Cable Modem + WiFi Router) allows aut... |
| CVE-2025-9638 | MEDIUM | 4.8 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educa... |
| CVE-2025-9368 | HIGH | 8.7 | 0.3% | Dec 9, 2025 | A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-o... |
| CVE-2025-6924 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2025-6923 | MEDIUM | 5.4 | 0.2% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2025-67599 | MEDIUM | 4.3 | 0.2% | Dec 9, 2025 | Missing Authorization vulnerability in WebToffee WebToffee eCommerce Marketing Automation decorator-woocommerce-email-cu... |
| CVE-2025-67598 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in PSM Plugins SupportCandy supportcandy allows Cross Site Request Forge... |
| CVE-2025-67597 | MEDIUM | 4.3 | 0.1% | Dec 9, 2025 | Missing Authorization vulnerability in Shahjahan Jewel Fluent Booking fluent-booking allows Exploiting Incorrectly Confi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now