2025 CVE Vulnerabilities
45,200 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62608 | CRITICAL | 9.1 | 0.5% | Nov 21, 2025 | MLX is an array framework for machine learning on Apple silicon. Prior to version 0.29.4, there is a heap buffer overflo... |
| CVE-2025-54866 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. From version 4.3.0 to befo... |
| CVE-2025-48502 | MEDIUM | 5.5 | 0.1% | Nov 21, 2025 | Improper input validation within AMD uprof can allow a local attacker to overwrite MSR registers, potentially resulting ... |
| CVE-2025-30201 | CRITICAL | 9.1 | 0.7% | Nov 21, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.13.0, a... |
| CVE-2025-29934 | MEDIUM | 5.3 | 0.1% | Nov 21, 2025 | A bug within some AMD CPUs could allow a local admin-privileged attacker to run a SEV-SNP guest using stale TLB entries,... |
| CVE-2025-64483 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Wazuh is a security detection, visibility, and compliance open source project. From version 4.9.0 to before 4.13.0, the ... |
| CVE-2025-13132 | HIGH | 7.4 | 0.2% | Nov 21, 2025 | This vulnerability allowed a site to enter fullscreen, after a user click, without a full-screen notification (toast) ap... |
| CVE-2025-13470 | HIGH | 7.7 | 0.3% | Nov 21, 2025 | In RNP version 0.18.0 a refactoring regression causes the symmetric session key used for Public-Key Encrypted Session K... |
| CVE-2025-12973 | HIGH | 7.2 | 0.9% | Nov 21, 2025 | The S2B AI Assistant – ChatBot, ChatGPT, OpenAI, Content & Image Generator plugin for WordPress is vulnerable to arbitra... |
| CVE-2025-12747 | MEDIUM | 5.3 | 0.3% | Nov 21, 2025 | The Tainacan plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.0 via ... |
| CVE-2025-41115 | CRITICAL | 9.8 | 17.3% | Nov 21, 2025 | SCIM provisioning was introduced in Grafana Enterprise and Grafana Cloud in April to improve how organizations manage us... |
| CVE-2025-13432 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Terraform state versions can be created by a user with specific but insufficient permissions in a Terraform Enterprise w... |
| CVE-2025-13357 | CRITICAL | 9.8 | 0.5% | Nov 21, 2025 | Vault’s Terraform Provider incorrectly set the default deny_null_bind parameter for the LDAP auth method to false by def... |
| CVE-2025-11127 | CRITICAL | 9.8 | 0.3% | Nov 21, 2025 | The Mstoreapp Mobile App WordPress plugin through 2.08 and Mstoreapp Mobile Multivendor through 9.0.1 do not properly ve... |
| CVE-2025-66115 | MEDIUM | 6.6 | 0.4% | Nov 21, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-66114 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in theme funda Show Variations as Single Products Woocommerce woo-show-single-variat... |
| CVE-2025-66113 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in ThemeAtelier Better Chat Support for Messenger better-chat-support allows Exploit... |
| CVE-2025-66112 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in WebToffee Accessibility Toolkit by WebYes accessibility-plus allows Exploiting In... |
| CVE-2025-66111 | MEDIUM | 6.5 | 0.1% | Nov 21, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nelio Software Nel... |
| CVE-2025-66110 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in bPlugins Tiktok Feed b-tiktok-feed allows Exploiting Incorrectly Configured Acces... |
| CVE-2025-66109 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Octolize Shipping Plugins Cart Weight for WooCommerce woo-cart-weight allows Expl... |
| CVE-2025-66108 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploitin... |
| CVE-2025-66107 | MEDIUM | 5.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Scott Paterson Subscriptions & Memberships for PayPal subscriptions-memberships-f... |
| CVE-2025-66106 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Essential Plugin Featured Post Creative featured-post-creative allows Exploiting ... |
| CVE-2025-66101 | MEDIUM | 4.3 | 0.2% | Nov 21, 2025 | Missing Authorization vulnerability in Sabuj Kundu CBX Bookmark & Favorite cbxwpbookmark allows Exploiting Incorrectly C... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now