2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13006 | MEDIUM | 5.3 | 0.2% | Dec 5, 2025 | The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in a... |
| CVE-2025-12417 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The SurveyFunnel – Survey Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the... |
| CVE-2025-66544 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66543 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66542 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66541 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66540 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66539 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66538 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66537 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-66536 | — | — | — | Dec 5, 2025 | Rejected reason: Not used |
| CVE-2025-27389 | MEDIUM | 5.1 | 0.1% | Dec 5, 2025 | A flaw exists in the verification of application installation sources within ColorOS. Under specific conditions, this is... |
| CVE-2025-13066 | HIGH | 8.8 | 0.5% | Dec 5, 2025 | The Demo Importer Plus plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including,... |
| CVE-2025-12804 | MEDIUM | 6.4 | 0.2% | Dec 5, 2025 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin 'bookingcalendar' ... |
| CVE-2025-11759 | MEDIUM | 4.3 | 0.1% | Dec 5, 2025 | The Backup, Restore and Migrate your sites with XCloner plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-62223 | MEDIUM | 4.3 | 0.4% | Dec 5, 2025 | User interface (ui) misrepresentation of critical information in Microsoft Edge for iOS allows an unauthorized attacker ... |
| CVE-2025-14052 | MEDIUM | 6.5 | 0.2% | Dec 5, 2025 | A vulnerability has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected by this vulnerability is the function get... |
| CVE-2025-66564 | HIGH | 7.5 | 0.4% | Dec 4, 2025 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest... |
| CVE-2025-66563 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user in... |
| CVE-2025-66561 | MEDIUM | 5.4 | 0.2% | Dec 4, 2025 | SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting ... |
| CVE-2025-66559 | HIGH | 8 | 0.3% | Dec 4, 2025 | Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising it... |
| CVE-2025-14051 | HIGH | 8.8 | 0.4% | Dec 4, 2025 | A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddres... |
| CVE-2025-13373 | HIGH | 8.7 | 0.4% | Dec 4, 2025 | Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could al... |
| CVE-2025-6946 | MEDIUM | 4.8 | 0.2% | Dec 4, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances vi... |
| CVE-2025-66509 | CRITICAL | 9.8 | 0.3% | Dec 4, 2025 | LaraDashboard is an all-In-one solution to start a Laravel Application. In 2.3.0 and earlier, the password reset flow tr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now