2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13080 | MEDIUM | 5.3 | 0.3% | Nov 18, 2025 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Drupal core allows Forceful Browsing.This i... |
| CVE-2025-12761 | LOW | 3.5 | 0.1% | Nov 18, 2025 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Simple mult... |
| CVE-2025-12760 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Email TFA allows Functionality Bypass.T... |
| CVE-2025-9977 | MEDIUM | 5.3 | 2.1% | Nov 18, 2025 | Value provided in one of POST parameters sent during the process of logging in to Times Software E-Payroll is not saniti... |
| CVE-2025-64996 | MEDIUM | 4.4 | 0.1% | Nov 18, 2025 | In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates worl... |
| CVE-2025-63800 | HIGH | 7.5 | 0.4% | Nov 18, 2025 | The password change endpoint in Open Source Point of Sale 3.4.1 allows users to set their account password to an empty s... |
| CVE-2025-63604 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | A code injection vulnerability exists in baryhuang/mcp-server-aws-resources-python 0.1.0 that allows remote code executi... |
| CVE-2025-63603 | MEDIUM | 6.5 | 0.8% | Nov 18, 2025 | A command injection vulnerability exists in the MCP Data Science Server's (reading-plus-ai/mcp-server-data-exploration) ... |
| CVE-2025-63602 | HIGH | 7.3 | 0.2% | Nov 18, 2025 | A vulnerability was discovered in Awesome Miner thru 11.2.4 that allows arbitrary read and write to kernel memory and MS... |
| CVE-2025-63408 | HIGH | 7.8 | 0.3% | Nov 18, 2025 | Local Agent DVR versions thru 6.6.1.0 are vulnerable to directory traversal that allows an unauthenticated local attacke... |
| CVE-2025-58122 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notifi... |
| CVE-2025-58121 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.... |
| CVE-2025-55074 | LOW | 3.5 | 0.1% | Nov 18, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to enforce access permissions on the Agents plugin which ... |
| CVE-2025-12383 | HIGH | 7.4 | 0.3% | Nov 18, 2025 | In Eclipse Jersey versions 2.45, 3.0.16, 3.1.9 a race condition can cause ignoring of critical SSL configurations - such... |
| CVE-2025-9312 | CRITICAL | 9.8 | 0.2% | Nov 18, 2025 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST AP... |
| CVE-2025-8084 | MEDIUM | 6.8 | 0.4% | Nov 18, 2025 | The AI Engine plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.... |
| CVE-2025-63892 | MEDIUM | 6.8 | 0.3% | Nov 18, 2025 | A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected is the function create_c... |
| CVE-2025-63883 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | A DOM-based cross-site scripting vulnerability exists in electic-shop v1.0 (Bhabishya-123/E-commerce). The site's client... |
| CVE-2025-59117 | MEDIUM | 4.8 | 0.2% | Nov 18, 2025 | Windu CMS is vulnerable to multiple Stored Cross-Site Scripting (XSS) vulnerabilities in the page editing endpoint windu... |
| CVE-2025-59116 | MEDIUM | 5.3 | 0.2% | Nov 18, 2025 | Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow ... |
| CVE-2025-59115 | MEDIUM | 5.4 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation... |
| CVE-2025-59114 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft spec... |
| CVE-2025-59113 | HIGH | 7.5 | 0.2% | Nov 18, 2025 | Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt co... |
| CVE-2025-59112 | MEDIUM | 6.5 | 0.1% | Nov 18, 2025 | Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft specia... |
| CVE-2025-59111 | MEDIUM | 6.5 | 0.3% | Nov 18, 2025 | Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET reques... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now