2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-41016 | HIGH | 8.7 | 0.2% | Nov 24, 2025 | Inadequate access control vulnerability in Davantis DFUSION v6.177.7, which allows unauthorised actors to extract images... |
| CVE-2025-40212 | CRITICAL | 9.8 | 0.2% | Nov 24, 2025 | In the Linux kernel, the following vulnerability has been resolved: nfsd: fix refcount leak in nfsd_set_fh_dentry() nf... |
| CVE-2025-12628 | MEDIUM | 6.3 | 0.2% | Nov 24, 2025 | The WP 2FA WordPress plugin does not generate backup codes with enough entropy, which could allow attackers to bypass th... |
| CVE-2025-41729 | HIGH | 7.5 | 0.4% | Nov 24, 2025 | An unauthenticated remote attacker can send a specially crafted Modbus read command to the device which leads to a denia... |
| CVE-2025-41087 | MEDIUM | 5.1 | 0.3% | Nov 24, 2025 | Cross-Site Scripting (XSS) vulnerability stored in tha Taclia web application, where the uploaded SVG images are not pro... |
| CVE-2025-12741 | HIGH | 7.7 | 0.2% | Nov 24, 2025 | A Looker user with Developer role could create a database connection using Denodo driver and, by manipulating LookML, ca... |
| CVE-2025-12740 | HIGH | 7.7 | 0.2% | Nov 24, 2025 | A Looker user with a Developer role could create a database connection using IBM DB2 driver and, by manipulating LookML,... |
| CVE-2025-12739 | HIGH | 7.3 | 0.3% | Nov 24, 2025 | An attacker with viewer permissions in Looker could craft a malicious URL that, when opened by a Looker admin, would exe... |
| CVE-2025-13596 | LOW | 2.7 | 0.3% | Nov 24, 2025 | A sensitive information disclosure vulnerability exists in the error handling component of ATISoluciones CIGES Applicati... |
| CVE-2025-13588 | MEDIUM | 6.3 | 0.2% | Nov 24, 2025 | A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown fun... |
| CVE-2025-13586 | HIGH | 7.2 | 0.3% | Nov 24, 2025 | A flaw has been found in SourceCodester Online Student Clearance System 1.0. Impacted is an unknown function of the file... |
| CVE-2025-13585 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of th... |
| CVE-2025-12629 | HIGH | 7.1 | 0.1% | Nov 24, 2025 | The Broken Link Manager WordPress plugin through 0.6.5 does not sanitise and escape a parameter before outputting it bac... |
| CVE-2025-12569 | MEDIUM | 4.7 | 0.2% | Nov 24, 2025 | The Guest posting / Frontend Posting / Front Editor WordPress plugin before 5.0.0 does not validate a parameter before ... |
| CVE-2025-12394 | MEDIUM | 5.9 | 0.3% | Nov 24, 2025 | The Backup Migration WordPress plugin before 2.0.0 does not properly generate its backup path in certain server configur... |
| CVE-2025-7402 | HIGH | 7.5 | 0.3% | Nov 24, 2025 | The Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager plugin for WordPress is vulnerable to time-based SQL In... |
| CVE-2025-13584 | LOW | 3.5 | 0.2% | Nov 24, 2025 | A security vulnerability has been detected in Eigenfocus up to 1.4.0. This vulnerability affects unknown code of the com... |
| CVE-2025-13583 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /... |
| CVE-2025-13589 | MEDIUM | 5.1 | 0.4% | Nov 24, 2025 | FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthentica... |
| CVE-2025-13582 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functiona... |
| CVE-2025-13581 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A vulnerability was identified in itsourcecode Student Information System 1.0. Affected by this vulnerability is an unkn... |
| CVE-2025-13580 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A vulnerability was determined in code-projects Library System 1.0. Affected is an unknown function of the file /mail.ph... |
| CVE-2025-13579 | HIGH | 8.8 | 0.3% | Nov 24, 2025 | A vulnerability was found in code-projects Library System 1.0. This impacts an unknown function of the file /return.php.... |
| CVE-2025-13578 | CRITICAL | 9.8 | 0.3% | Nov 24, 2025 | A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.... |
| CVE-2025-13577 | MEDIUM | 5.4 | 0.2% | Nov 24, 2025 | A flaw has been found in PHPGurukul Hostel Management System 2.1. The impacted element is an unknown function of the fil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now