2025 CVE Vulnerabilities
45,185 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12712 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Shouty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shouty shortcode in all versions up... |
| CVE-2025-12670 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The wp-twitpic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'twitpic... |
| CVE-2025-12666 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The Google Drive upload and download link plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'lin... |
| CVE-2025-12649 | MEDIUM | 6.4 | 0.2% | Nov 27, 2025 | The SortTable Post plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter in the sortt... |
| CVE-2025-12579 | MEDIUM | 5.3 | 0.2% | Nov 27, 2025 | The Reuters Direct plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-12578 | MEDIUM | 4.3 | 0.1% | Nov 27, 2025 | The Reuters Direct plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-0658 | HIGH | 8.7 | 0.3% | Nov 27, 2025 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The dev... |
| CVE-2025-0657 | HIGH | 8.8 | 0.3% | Nov 27, 2025 | A weakness in Automated Logic and Carrier i-Vu Gen5 router on driver version drv_gen5_106-01-2380, allows malformed... |
| CVE-2025-66040 | LOW | 3.6 | 0.1% | Nov 27, 2025 | Spotipy is a Python library for the Spotify Web API. Prior to version 2.25.2, there is a cross-site scripting (XSS) vuln... |
| CVE-2025-66035 | HIGH | 7.7 | 0.6% | Nov 26, 2025 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2025-66031 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Uncontrolled R... |
| CVE-2025-66030 | MEDIUM | 5.3 | 0.3% | Nov 26, 2025 | Forge (also called `node-forge`) is a native implementation of Transport Layer Security in JavaScript. An Integer Overfl... |
| CVE-2025-64344 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64335 | HIGH | 7.5 | 0.4% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64334 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64333 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64332 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64331 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-64330 | HIGH | 7.5 | 0.3% | Nov 26, 2025 | Suricata is a network IDS, IPS and NSM engine developed by the OISF (Open Information Security Foundation) and the Suric... |
| CVE-2025-62593 | HIGH | 8.8 | 0.4% | Nov 26, 2025 | Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited... |
| CVE-2025-40934 | CRITICAL | 9.3 | 0.1% | Nov 26, 2025 | XML-Sig versions 0.27 through 0.67 for Perl incorrectly validates XML files if signatures are omitted. An attacker can ... |
| CVE-2025-65202 | HIGH | 8 | 7.2% | Nov 26, 2025 | TRENDnet TEW-657BRM 1.00.1 has an authenticated remote OS command injection vulnerability in the setup.cgi binary, explo... |
| CVE-2025-7449 | MEDIUM | 6.5 | 0.4% | Nov 26, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.4.5, 18.5 before 18.5.3, and 18... |
| CVE-2025-6195 | MEDIUM | 4.3 | 0.3% | Nov 26, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6... |
| CVE-2025-65670 | MEDIUM | 4.3 | 0.2% | Nov 26, 2025 | An Insecure Direct Object Reference (IDOR) in classroomio 0.1.13 allows students to access sensitive admin/teacher endpo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now