2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12823 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The CSV to SortTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'csv' shortcode in all ve... |
| CVE-2025-12775 | HIGH | 8.8 | 0.5% | Nov 18, 2025 | The WP Dropzone plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, and inc... |
| CVE-2025-12528 | HIGH | 8.1 | 0.6% | Nov 18, 2025 | The Pie Forms for WP plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1... |
| CVE-2025-12411 | HIGH | 7.1 | 0.2% | Nov 18, 2025 | The Premmerce Wholesale Pricing for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'ID' paramet... |
| CVE-2025-12406 | MEDIUM | 6.1 | 0.1% | Nov 18, 2025 | The Project Honey Pot Spam Trap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, ... |
| CVE-2025-12404 | MEDIUM | 6.1 | 0.1% | Nov 18, 2025 | The Like-it plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. ... |
| CVE-2025-12372 | MEDIUM | 4.3 | 0.2% | Nov 18, 2025 | The Permalinks Cascade plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including,... |
| CVE-2025-12173 | MEDIUM | 4.3 | 0.1% | Nov 18, 2025 | The WP Admin Microblog plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-12078 | MEDIUM | 6.1 | 0.2% | Nov 18, 2025 | The ArtiBot Free Chat Bot for WebSites plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PostMess... |
| CVE-2025-11868 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The everviz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `everviz` shortcode attributes in ... |
| CVE-2025-11620 | HIGH | 7.2 | 0.3% | Nov 18, 2025 | The Multiple Roles per User plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2025-8727 | HIGH | 7.2 | 0.3% | Nov 18, 2025 | There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web ... |
| CVE-2025-8404 | MEDIUM | 5.5 | 0.3% | Nov 18, 2025 | Stack buffer overflow vulnerability exists in the Supermicro BMC Shared library. An authenticated attacker with access t... |
| CVE-2025-8076 | HIGH | 7.2 | 0.3% | Nov 18, 2025 | There is a vulnerability in the Supermicro BMC web function at Supermicro MBD-X13SEDW-F. After logging into the BMC Web ... |
| CVE-2025-11267 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_veu_custom_... |
| CVE-2025-11265 | MEDIUM | 6.4 | 0.2% | Nov 18, 2025 | The VK All in One Expansion Unit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vkExUnit_cta... |
| CVE-2025-10089 | HIGH | 7.7 | 0.1% | Nov 18, 2025 | Uncontrolled Search Path Element Vulnerability in Setting and Operation Application for Lighting Control System MILCO.S ... |
| CVE-2025-7623 | MEDIUM | 5.4 | 0.2% | Nov 18, 2025 | Stack-based buffer overflow in the SMASH-CLP shell. An authenticated attacker with SSH access to the BMC can exploit a s... |
| CVE-2025-12524 | MEDIUM | 5.4 | 0.3% | Nov 18, 2025 | The Post Type Switcher plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and inc... |
| CVE-2025-48593 | HIGH | 8 | 0.9% | Nov 18, 2025 | In bta_hf_client_cb_init of bta_hf_client_main.cc, there is a possible remote code execution due to a use after free. Th... |
| CVE-2025-64734 | LOW | 2.4 | 0.1% | Nov 18, 2025 | Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access... |
| CVE-2025-52578 | MEDIUM | 5.7 | 0.1% | Nov 18, 2025 | Incorrect Usage of Seeds in Pseudo-Random Number Generator (CWE- 335) vulnerability in the High Sec ELM may allow a soph... |
| CVE-2025-52457 | MEDIUM | 5.7 | 0.1% | Nov 18, 2025 | Observable Timing Discrepancy (CWE-208) in HBUS devices may allow an attacker with physical access to the device to extr... |
| CVE-2025-12974 | HIGH | 8.1 | 0.6% | Nov 18, 2025 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-8693 | HIGH | 8.8 | 1.0% | Nov 18, 2025 | A post-authentication command injection vulnerability in the "priv" parameter of Zyxel DX3300-T0 firmware version 5.50(A... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now