2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12025 | MEDIUM | 4.4 | 0.2% | Nov 25, 2025 | The YouTube Subscribe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versio... |
| CVE-2025-12003 | HIGH | 8.2 | 0.6% | Nov 25, 2025 | A path traversal vulnerability has been identified in WebDAV, which may allow unauthenticated remote attackers to impact... |
| CVE-2025-13644 | HIGH | 7.5 | 0.3% | Nov 25, 2025 | MongoDB Server may experience an invariant failure during batched delete operations when handling documents. The issue a... |
| CVE-2025-13643 | MEDIUM | 6.5 | 0.2% | Nov 25, 2025 | A user with access to the cluster with a limited set of privilege actions may be able to terminate queries that are bein... |
| CVE-2025-12742 | HIGH | 7.5 | 0.2% | Nov 25, 2025 | A Looker user with a Developer role could cause Looker to execute a malicious command, due to insecure processing of Ter... |
| CVE-2025-64730 | MEDIUM | 6.1 | 0.2% | Nov 25, 2025 | Cross-site scripting vulnerability exists in SNC-CX600W all versions. If this vulnerability is exploited, an arbitrary s... |
| CVE-2025-64304 | MEDIUM | 5.1 | 0.1% | Nov 25, 2025 | "FOD" App uses hard-coded cryptographic keys, which may allow a local unauthenticated attacker to retrieve the cryptogra... |
| CVE-2025-62497 | MEDIUM | 6.5 | 0.1% | Nov 25, 2025 | Cross-site request forgery vulnerability exists in SNC-CX600W versions prior to Ver.2.8.0. If a user accesses a speciall... |
| CVE-2025-13559 | CRITICAL | 9.8 | 0.3% | Nov 25, 2025 | The EduKart Pro plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.0.3. ... |
| CVE-2025-13558 | MEDIUM | 5.4 | 0.2% | Nov 25, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-13507 | HIGH | 7.1 | 0.2% | Nov 25, 2025 | Inconsistent object size validation in time series processing logic may result in later processing of oversized BSON doc... |
| CVE-2025-13068 | HIGH | 7.2 | 0.2% | Nov 25, 2025 | The Telegram Bot & Channel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Telegram username i... |
| CVE-2025-12893 | MEDIUM | 5.4 | 0.1% | Nov 25, 2025 | Clients may successfully perform a TLS handshake with a MongoDB server despite presenting a client certificate not align... |
| CVE-2025-66187 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66186 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66185 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66184 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66183 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66182 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66181 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66180 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-66179 | — | — | — | Nov 25, 2025 | Rejected reason: Not used |
| CVE-2025-10646 | MEDIUM | 4.3 | 0.2% | Nov 25, 2025 | The Search Exclude plugin for WordPress is vulnerable to unauthorized modification of data due to a insufficient capabil... |
| CVE-2025-6389 | CRITICAL | 9.8 | 43.4% | Nov 25, 2025 | The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8... |
| CVE-2025-59373 | HIGH | 8.5 | 0.1% | Nov 25, 2025 | A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now