2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12359 | MEDIUM | 5.4 | 0.2% | Nov 19, 2025 | The Responsive Lightbox & Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up t... |
| CVE-2025-12174 | MEDIUM | 6.5 | 0.2% | Nov 19, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-12057 | CRITICAL | 9.8 | 0.4% | Nov 19, 2025 | The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate ... |
| CVE-2025-12426 | HIGH | 7.5 | 0.3% | Nov 19, 2025 | The Quiz Maker plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-12349 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The Icegram Express - Email Subscribers, Newsletters and Marketing Automation Plugin for WordPress is vulnerable to Auth... |
| CVE-2025-6251 | MEDIUM | 6.4 | 0.2% | Nov 19, 2025 | The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via $item['fi... |
| CVE-2025-65941 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65940 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65939 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65938 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65937 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65936 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65935 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65934 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-65933 | — | — | — | Nov 19, 2025 | Rejected reason: Not used |
| CVE-2025-13051 | CRITICAL | 9.3 | 0.2% | Nov 19, 2025 | When the service of ABP and AES is installed in a directory writable by non-administrative users, an attacker can replac... |
| CVE-2025-12777 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to authorization bypass in all versions up to, and incl... |
| CVE-2025-12770 | MEDIUM | 5.3 | 0.3% | Nov 19, 2025 | The New User Approve plugin for WordPress is vulnerable to unauthorized data disclosure in all versions up to, and inclu... |
| CVE-2025-12427 | MEDIUM | 5.3 | 0.2% | Nov 19, 2025 | The YITH WooCommerce Wishlist plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up ... |
| CVE-2025-13225 | MEDIUM | 6 | 0.1% | Nov 19, 2025 | Tanium addressed an arbitrary file deletion vulnerability in TanOS. |
| CVE-2025-12852 | HIGH | 8.4 | 0.1% | Nov 19, 2025 | DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC ... |
| CVE-2025-65093 | MEDIUM | 5.5 | 3.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a boolean-based ... |
| CVE-2025-65015 | HIGH | 7.5 | 0.3% | Nov 18, 2025 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2025-65014 | LOW | 3.7 | 0.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a weak password ... |
| CVE-2025-65013 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring tool. Prior to version 25.11.0, a reflected cros... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now