2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14286 | HIGH | 7.5 | 0.6% | Dec 9, 2025 | A vulnerability was determined in Tenda AC9 15.03.05.14_multi. Affected by this vulnerability is an unknown functionalit... |
| CVE-2025-14284 | MEDIUM | 6.1 | 0.3% | Dec 9, 2025 | Versions of the package @tiptap/extension-link before 2.10.4 are vulnerable to Cross-site Scripting (XSS) due to unsanit... |
| CVE-2025-13662 | HIGH | 7.8 | 0.5% | Dec 9, 2025 | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to ... |
| CVE-2025-13661 | HIGH | 8 | 1.1% | Dec 9, 2025 | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write ... |
| CVE-2025-13659 | HIGH | 8.8 | 1.6% | Dec 9, 2025 | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a... |
| CVE-2025-13642 | MEDIUM | 5.4 | 0.4% | Dec 9, 2025 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePres... |
| CVE-2025-13604 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scrip... |
| CVE-2025-13428 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | A vulnerability exists in the SecOps SOAR server. The custom integrations feature allowed an authenticated user with an ... |
| CVE-2025-13071 | HIGH | 7.1 | 0.2% | Dec 9, 2025 | The Custom Admin Menu WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back ... |
| CVE-2025-13070 | MEDIUM | 6.6 | 0.4% | Dec 9, 2025 | The CSV to SortTable WordPress plugin through 4.2 does not validate some shortcode attributes before using them to gener... |
| CVE-2025-13031 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.13 does not sanitize and escape some of its settings, which c... |
| CVE-2025-12807 | HIGH | 8.7 | 0.4% | Dec 9, 2025 | A security issue was discovered in DataMosaix Private Cloud, allowing users with low privilege to perform sensitive data... |
| CVE-2025-12705 | HIGH | 7.2 | 0.3% | Dec 9, 2025 | The Social Reviews & Recommendations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several param... |
| CVE-2025-12558 | MEDIUM | 4.3 | 0.3% | Dec 9, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2025-12504 | CRITICAL | 9.8 | 0.5% | Dec 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Talent Software UN... |
| CVE-2025-12381 | HIGH | 7.8 | 0.1% | Dec 9, 2025 | Improper Privilege Management vulnerability in AlgoSec Firewall Analyzer on Linux, 64 bit allows Privilege Escalation, P... |
| CVE-2025-11022 | CRITICAL | 9.6 | 0.5% | Dec 9, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Personal Project Panilux allows Cross Site Request Forgery. This ... |
| CVE-2025-10876 | MEDIUM | 5.3 | 0.3% | Dec 9, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Soft... |
| CVE-2025-10655 | HIGH | 8.8 | 0.5% | Dec 9, 2025 | SQL Injection in Frappe HelpDesk in the dashboard get_dashboard_data due to unsafe concatenation of user-controlled para... |
| CVE-2025-10573 | MEDIUM | 6.1 | 29.5% | Dec 9, 2025 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute ... |
| CVE-2025-66491 | MEDIUM | 5.9 | 0.2% | Dec 9, 2025 | Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in... |
| CVE-2025-66490 | MEDIUM | 6.5 | 0.3% | Dec 9, 2025 | Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests us... |
| CVE-2025-66481 | CRITICAL | 9.6 | 0.5% | Dec 9, 2025 | DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable... |
| CVE-2025-66470 | MEDIUM | 6.1 | 0.2% | Dec 9, 2025 | NiceGUI is a Python-based UI framework. Versions 3.3.1 and below are subject to a XSS vulnerability through the ui.inter... |
| CVE-2025-14285 | CRITICAL | 9.8 | 0.3% | Dec 9, 2025 | A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of th... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now