2025 CVE Vulnerabilities
45,202 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10437 | CRITICAL | 9.8 | 0.3% | Nov 19, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eksagate Electroni... |
| CVE-2025-64408 | MEDIUM | 6.3 | 9.4% | Nov 19, 2025 | Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controlla... |
| CVE-2025-13395 | HIGH | 7.3 | 0.3% | Nov 19, 2025 | A security flaw has been discovered in codehub666 94list up to 5831c8240e99a72b7d3508c79ef46ae4b96befe8. The impacted el... |
| CVE-2025-12472 | HIGH | 7.1 | 0.2% | Nov 19, 2025 | An attacker with a Looker Developer role could manipulate a LookML project to exploit a race condition during Git direct... |
| CVE-2025-58412 | MEDIUM | 6.1 | 0.1% | Nov 19, 2025 | A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0... |
| CVE-2025-11230 | HIGH | 7.5 | 0.5% | Nov 19, 2025 | Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially ... |
| CVE-2025-0351 | — | — | — | Nov 19, 2025 | Rejected reason: Voluntarily withdrawn |
| CVE-2025-11446 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know... |
| CVE-2025-13206 | MEDIUM | 6.1 | 0.2% | Nov 19, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2025-13035 | HIGH | 8 | 0.3% | Nov 19, 2025 | The Code Snippets plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.9.1. ... |
| CVE-2025-12484 | HIGH | 7.2 | 0.3% | Nov 19, 2025 | The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for... |
| CVE-2025-13085 | MEDIUM | 4.3 | 0.2% | Nov 19, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Improper Authorization leading to Sensitive Post Meta... |
| CVE-2025-12535 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The SureForms plugin for WordPress is vulnerable to Cross-Site Request Forgery Bypass in all versions up to, and includi... |
| CVE-2025-12056 | HIGH | 8.3 | 0.2% | Nov 19, 2025 | Out-of-bounds Read in Shelly Pro 3EM (before v1.4.4) allows Overread Buffers. |
| CVE-2025-11243 | HIGH | 8.3 | 0.4% | Nov 19, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Shelly Pro 4PM (before v1.6) allows Excessive Allo... |
| CVE-2025-13145 | HIGH | 7.2 | 0.4% | Nov 19, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to PHP Object Injection in al... |
| CVE-2025-13054 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2025-12878 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The FunnelKit – Funnel Builder for WooCommerce Checkout plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2025-12842 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The Booking Plugin for WordPress Appointments – Time Slot plugin for WordPress is vulnerable to unauthorized email sendi... |
| CVE-2025-12822 | MEDIUM | 4.3 | 0.2% | Nov 19, 2025 | The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing c... |
| CVE-2025-12814 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to unauthorized modification of data due to n incorrect ... |
| CVE-2025-12751 | MEDIUM | 4.3 | 0.2% | Nov 19, 2025 | The WSChat – WordPress Live Chat plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-12710 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The Pet-Manager – Petfinder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the kwm-petfinder shor... |
| CVE-2025-12646 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | The Community Events plugin for WordPress is vulnerable to SQL Injection via the 'dayofyear' parameter in all versions u... |
| CVE-2025-12359 | MEDIUM | 5.4 | 0.2% | Nov 19, 2025 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now