2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13955 | CRITICAL | 9.3 | 0.2% | Dec 10, 2025 | Predictable default Wi-Fi Password in Access Point functionality in EZCast Pro II before version 1.17478.177 allows atta... |
| CVE-2025-13954 | CRITICAL | 9.3 | 0.2% | Dec 10, 2025 | Hard-coded cryptographic keys in Admin UI of EZCast Pro II before version 1.17478.177 allows attackers to bypass authori... |
| CVE-2025-12952 | HIGH | 8.7 | 0.3% | Dec 10, 2025 | A privilege escalation vulnerability exists in Google Cloud's Dialogflow CX. Dialogflow agent developers with Webhook e... |
| CVE-2025-9571 | HIGH | 8.7 | 0.4% | Dec 10, 2025 | A remote code execution (RCE) vulnerability exists in Google Cloud Data Fusion. A user with permissions to upload artifa... |
| CVE-2025-13073 | HIGH | 7.1 | 0.2% | Dec 10, 2025 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting... |
| CVE-2025-13072 | HIGH | 7.1 | 0.2% | Dec 10, 2025 | The HandL UTM Grabber / Tracker WordPress plugin before 2.8.1 does not sanitize and escape a parameter before outputting... |
| CVE-2025-13339 | HIGH | 7.5 | 2.2% | Dec 10, 2025 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Path Traversal in all versions up to, and in... |
| CVE-2025-9056 | MEDIUM | 5.3 | 0.2% | Dec 10, 2025 | Unprotected service in the AudioLink component allows a local attacker to overwrite system files via unauthorized servic... |
| CVE-2025-67613 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67612 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67611 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67610 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67609 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67608 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67607 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67606 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-67605 | — | — | — | Dec 10, 2025 | Rejected reason: Not used |
| CVE-2025-13677 | MEDIUM | 4.9 | 0.4% | Dec 10, 2025 | The Simple Download Counter plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2... |
| CVE-2025-13613 | CRITICAL | 9.8 | 0.4% | Dec 10, 2025 | The Elated Membership plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, ... |
| CVE-2025-67507 | HIGH | 8.1 | 0.3% | Dec 10, 2025 | Filament is a collection of full-stack components for accelerated Laravel development. Versions 4.0.0 through 4.3.0 cont... |
| CVE-2025-67506 | CRITICAL | 9.8 | 1.6% | Dec 10, 2025 | PipesHub is a fully extensible workplace AI platform for enterprise search and workflow automation. Versions prior to 0.... |
| CVE-2025-67485 | MEDIUM | 5.3 | 0.2% | Dec 10, 2025 | mad-proxy is a Python-based HTTP/HTTPS proxy server for detection and blocking of malicious web activity using custom se... |
| CVE-2025-67503 | — | — | — | Dec 10, 2025 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2025-67502 | MEDIUM | 6.1 | 0.2% | Dec 10, 2025 | Taguette is an open source qualitative research tool. In versions 1.5.1 and below, attackers can craft malicious URLs t... |
| CVE-2025-67501 | HIGH | 8.8 | 0.4% | Dec 10, 2025 | WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now