2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13442 | CRITICAL | 9.8 | 17.6% | Nov 20, 2025 | A security vulnerability has been detected in UTT 进取 750W up to 3.2.2-191225. Affected by this vulnerability is the func... |
| CVE-2025-13435 | HIGH | 8.1 | 0.6% | Nov 20, 2025 | A security vulnerability has been detected in Dreampie Resty up to 1.3.1.SNAPSHOT. This affects the function Request of ... |
| CVE-2025-13434 | HIGH | 7.5 | 0.4% | Nov 20, 2025 | A weakness has been identified in jameschz Hush Framework 2.0. The impacted element is an unknown function of the file H... |
| CVE-2025-13433 | HIGH | 7.3 | 0.1% | Nov 20, 2025 | A security flaw has been discovered in Muse Group MuseHub 2.1.0.1567. The affected element is an unknown function of the... |
| CVE-2025-12778 | MEDIUM | 5.3 | 0.2% | Nov 20, 2025 | The Ultimate Member Widgets for Elementor – WordPress User Directory plugin for WordPress is vulnerable to unauthorized ... |
| CVE-2025-12502 | MEDIUM | 6.8 | 0.2% | Nov 20, 2025 | The attention-bar WordPress plugin through 0.7.2.1 does not sanitize and escape a parameter before using it in a SQL sta... |
| CVE-2025-12414 | CRITICAL | 9.2 | 0.4% | Nov 20, 2025 | An attacker could take over a Looker account in a Looker instance configured with OIDC authentication, due to email addr... |
| CVE-2025-11676 | HIGH | 7.1 | 0.2% | Nov 20, 2025 | Improper input validation vulnerability in TP-Link System Inc. TL-WR940N V6 (UPnP modules), which allows unauthenticated... |
| CVE-2025-0645 | HIGH | 7.2 | 0.3% | Nov 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Narkom Communication and Software Technologies Trade Lt... |
| CVE-2025-0643 | HIGH | 7.2 | 0.3% | Nov 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Narkom Comm... |
| CVE-2025-13424 | CRITICAL | 9.8 | 0.3% | Nov 20, 2025 | A vulnerability has been found in Campcodes Supplier Management System 1.0. This affects an unknown function of the file... |
| CVE-2025-13423 | HIGH | 7.2 | 0.3% | Nov 20, 2025 | A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function ... |
| CVE-2025-13422 | CRITICAL | 9.8 | 0.4% | Nov 20, 2025 | A vulnerability was detected in freeprojectscodes Sports Club Management System 1.0. The affected element is an unknown ... |
| CVE-2025-4042 | — | — | — | Nov 19, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-13421 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A security vulnerability has been detected in itsourcecode Human Resource Management System 1.0. Impacted is an unknown ... |
| CVE-2025-13420 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A weakness has been identified in itsourcecode Human Resource Management System 1.0. This issue affects some unknown pro... |
| CVE-2025-13415 | MEDIUM | 5.4 | 0.2% | Nov 19, 2025 | A vulnerability was identified in icret EasyImages up to 2.8.6. This affects an unknown part of the file /app/upload.php... |
| CVE-2025-11884 | LOW | 2.3 | 0.2% | Nov 19, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in opentext uC... |
| CVE-2025-11001 | HIGH | 7.8 | 27.0% | Nov 19, 2025 | 7-Zip ZIP File Parsing Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacke... |
| CVE-2025-63719 | HIGH | 7.3 | 0.2% | Nov 19, 2025 | Campcodes Online Hospital Management System 1.0 is vulnerable to SQL Injection in /admin/index.php via the parameter use... |
| CVE-2025-63371 | HIGH | 7.5 | 0.6% | Nov 19, 2025 | Milos Paripovic OneCommander 3.102.0.0 is vulnerable to Directory Traversal. The vulnerability resides in the ZIP file p... |
| CVE-2025-58181 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, al... |
| CVE-2025-47914 | MEDIUM | 5.3 | 0.5% | Nov 19, 2025 | SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the progra... |
| CVE-2025-13412 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | A vulnerability was determined in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this issue is some unkn... |
| CVE-2025-13411 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | A vulnerability was found in Campcodes Retro Basketball Shoes Online Store 1.0. Affected by this vulnerability is an unk... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now