2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-14010 | MEDIUM | 5.5 | 0.1% | Dec 4, 2025 | A flaw was found in ansible-collection-community-general. This vulnerability allows for information exposure (IE) of sen... |
| CVE-2025-12826 | MEDIUM | 4.8 | 0.3% | Dec 4, 2025 | The Custom Post Type UI plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including,... |
| CVE-2025-12782 | MEDIUM | 4.3 | 0.2% | Dec 4, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to authorization bypass in all versions u... |
| CVE-2025-13513 | MEDIUM | 6.1 | 0.2% | Dec 4, 2025 | The Clik stats plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `$_SERVER['PHP_SELF']` param... |
| CVE-2025-11727 | HIGH | 7.2 | 0.2% | Dec 4, 2025 | The Omnichannel for WooCommerce: Google, Amazon, eBay & Walmart Integration – Powered by Codisto plugin for WordPress is... |
| CVE-2025-11379 | MEDIUM | 5.3 | 0.3% | Dec 4, 2025 | The WebP Express plugin for WordPress is vulnerable to information exposure via config files in all versions up to, and ... |
| CVE-2025-62173 | HIGH | 8.6 | 0.2% | Dec 4, 2025 | ## Summary Authenticated SQL Injection Vulnerability in Endpoint Module Rest API |
| CVE-2025-66404 | HIGH | 8.8 | 1.3% | Dec 3, 2025 | MCP Server Kubernetes is an MCP Server that can connect to a Kubernetes cluster and manage it. Prior to 2.9.8, there is ... |
| CVE-2025-66293 | HIGH | 7.1 | 0.3% | Dec 3, 2025 | LIBPNG is a reference library for use in applications that read, create, and manipulate PNG (Portable Network Graphics) ... |
| CVE-2025-65868 | HIGH | 7.5 | 0.4% | Dec 3, 2025 | XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted b... |
| CVE-2025-64055 | CRITICAL | 9.8 | 0.5% | Dec 3, 2025 | An issue was discovered in Fanvil x210 V2 2.12.20 allowing unauthenticated attackers on the local network to access admi... |
| CVE-2025-66489 | CRITICAL | 9.8 | 0.8% | Dec 3, 2025 | Cal.com is open-source scheduling software. Prior to 5.9.8, A flaw in the login credentials provider allows an attacker ... |
| CVE-2025-66453 | HIGH | 7.5 | 0.2% | Dec 3, 2025 | Rhino is an open-source implementation of JavaScript written entirely in Java. Prior to 1.8.1, 1.7.15.1, and 1.7.14.1, w... |
| CVE-2025-66411 | MEDIUM | 5.5 | 0.2% | Dec 3, 2025 | Coder allows organizations to provision remote development environments via Terraform. Prior to 2.26.5, 2.27.7, and 2.28... |
| CVE-2025-66406 | MEDIUM | 5 | 0.1% | Dec 3, 2025 | Step CA is an online certificate authority for secure, automated certificate management for DevOps. Prior to 0.29.0, the... |
| CVE-2025-65345 | MEDIUM | 6.5 | 0.5% | Dec 3, 2025 | alexusmai laravel-file-manager 3.3.1 and below is vulnerable to Directory Traversal. The zip/archiving functionality all... |
| CVE-2025-65097 | MEDIUM | 6.5 | 0.2% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-65096 | MEDIUM | 4.3 | 0.2% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-65027 | HIGH | 7.6 | 0.3% | Dec 3, 2025 | RomM (ROM Manager) allows users to scan, enrich, browse and play their game collections with a clean and responsive inte... |
| CVE-2025-61727 | MEDIUM | 6.5 | 0.3% | Dec 3, 2025 | An excluded subdomain constraint in a certificate chain does not restrict the usage of wildcard SANs in the leaf certifi... |
| CVE-2025-50361 | MEDIUM | 5.1 | 0.2% | Dec 3, 2025 | Buffer Overflow was found in SmallBASIC community SmallBASIC with SDL Before v12_28, and commit sha:298a1d495355959db364... |
| CVE-2025-13086 | HIGH | 7.5 | 0.6% | Dec 3, 2025 | Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows... |
| CVE-2025-12385 | HIGH | 8.7 | 0.3% | Dec 3, 2025 | Allocation of Resources Without Limits or Throttling, Improper Validation of Specified Quantity in Input vulnerability i... |
| CVE-2025-66222 | CRITICAL | 9.6 | 0.5% | Dec 3, 2025 | DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting... |
| CVE-2025-66220 | HIGH | 7.1 | 0.2% | Dec 3, 2025 | Envoy is a high-performance edge/middle/service proxy. In 1.33.12, 1.34.10, 1.35.6, 1.36.2, and earlier, Envoy’s mTLS ce... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now