2025 CVE Vulnerabilities
45,184 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58294 | MEDIUM | 5.5 | 0.1% | Nov 28, 2025 | Permission control vulnerability in the print module. Impact: Successful exploitation of this vulnerability may affect s... |
| CVE-2025-66361 | MEDIUM | 6.5 | 0.2% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. Sensitive information is exposed in System Processes for an extended p... |
| CVE-2025-66360 | HIGH | 8.8 | 0.3% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. An improperly configured access control policy exposes sensitive Logpo... |
| CVE-2025-66359 | MEDIUM | 6.1 | 0.2% | Nov 28, 2025 | An issue was discovered in Logpoint before 7.7.0. Insufficient input validation and a lack of output escaping in multipl... |
| CVE-2025-13338 | — | — | — | Nov 27, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-3261 | — | — | — | Nov 27, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12421 | CRITICAL | 9.9 | 0.3% | Nov 27, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that t... |
| CVE-2025-12559 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team em... |
| CVE-2025-13765 | MEDIUM | 4.3 | 0.3% | Nov 27, 2025 | Exposure of email service credentials to users without administrative rights in Devolutions Server.This issue affects De... |
| CVE-2025-13758 | LOW | 3.5 | 0.3% | Nov 27, 2025 | Exposure of credentials in unintended requests in Devolutions Server.This issue affects Server: through 2025.2.20, throu... |
| CVE-2025-13757 | HIGH | 8.8 | 0.5% | Nov 27, 2025 | SQL Injection vulnerability in last usage logs in Devolutions Server.This issue affects Devolutions Server: through 2025... |
| CVE-2025-12419 | CRITICAL | 9.9 | 0.3% | Nov 27, 2025 | Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validat... |
| CVE-2025-8890 | CRITICAL | 9.3 | 0.9% | Nov 27, 2025 | Firmware in SDMC NE6037 routers prior to version 7.1.12.2.44 has a network diagnostics tool vulnerable to a shell comman... |
| CVE-2025-13692 | HIGH | 7.2 | 0.3% | Nov 27, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uplo... |
| CVE-2025-12140 | CRITICAL | 9.3 | 0.4% | Nov 27, 2025 | The application contains an insecure 'redirectToUrl' mechanism that incorrectly processes the value of the 'redirectUrlP... |
| CVE-2025-12971 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | The Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager plugin for WordPress is vul... |
| CVE-2025-59454 | MEDIUM | 4.3 | 0.3% | Nov 27, 2025 | In Apache CloudStack, a gap in access control checks affected the APIs - createNetworkACL - listNetworkACLs - listResour... |
| CVE-2025-59302 | MEDIUM | 4.7 | 0.4% | Nov 27, 2025 | In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following ... |
| CVE-2025-54057 | MEDIUM | 6.1 | 0.6% | Nov 27, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache SkyWalking. This ... |
| CVE-2025-59890 | HIGH | 7.3 | 0.1% | Nov 27, 2025 | Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths ... |
| CVE-2025-13742 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | Emails sent by pretix can utilize placeholders that will be filled with customer data. For example, when {name} is used ... |
| CVE-2025-10476 | MEDIUM | 4.3 | 0.2% | Nov 27, 2025 | The WP Fastest Cache plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-59026 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content uploaded as file can be used to execute script code when following attacker-controlled links. Unintend... |
| CVE-2025-59025 | MEDIUM | 6.1 | 0.2% | Nov 27, 2025 | Malicious e-mail content can be used to execute script code. Unintended actions can be executed in the context of the us... |
| CVE-2025-30190 | MEDIUM | 5.4 | 0.2% | Nov 27, 2025 | Malicious content at office documents can be used to inject script code when editing a document. Unintended actions can ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now