2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13191 | CRITICAL | 9.8 | 0.8% | Nov 15, 2025 | A vulnerability was determined in D-Link DIR-816L 2_06_b09_beta. This issue affects the function soapcgi_main of the fil... |
| CVE-2025-13190 | HIGH | 8.8 | 0.7% | Nov 15, 2025 | A vulnerability was found in D-Link DIR-816L 2_06_b09_beta. This vulnerability affects the function scandir_main of the ... |
| CVE-2025-12849 | MEDIUM | 5.3 | 0.3% | Nov 15, 2025 | The Contest Gallery plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 28.... |
| CVE-2025-8994 | MEDIUM | 6.5 | 0.2% | Nov 15, 2025 | The Project Management, Team Collaboration, Kanban Board, Gantt Charts, Task Manager and More – WP Project Manager plugi... |
| CVE-2025-13189 | CRITICAL | 9.8 | 0.8% | Nov 15, 2025 | A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena... |
| CVE-2025-12847 | MEDIUM | 4.3 | 0.2% | Nov 15, 2025 | The All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic plugin for WordPress is vulnerable to ... |
| CVE-2025-12494 | MEDIUM | 4.3 | 0.2% | Nov 15, 2025 | The Image Gallery – Photo Grid & Video Gallery plugin for WordPress is vulnerable to arbitrary file deletion due to insu... |
| CVE-2025-65072 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65071 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65070 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65069 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65068 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65067 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65066 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65065 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-65064 | — | — | — | Nov 15, 2025 | Rejected reason: Not used |
| CVE-2025-12182 | MEDIUM | 4.3 | 0.2% | Nov 15, 2025 | The Qi Blocks plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the `resize... |
| CVE-2025-9317 | HIGH | 8.4 | 0.1% | Nov 15, 2025 | The vulnerability, if exploited, could allow a miscreant with read access to Edge Project files or Edge Offline Cache f... |
| CVE-2025-8386 | HIGH | 7.2 | 0.1% | Nov 15, 2025 | The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper w... |
| CVE-2025-64309 | HIGH | 7.4 | 0.2% | Nov 15, 2025 | The affected product discloses device telemetry, configuration, and sensitive information via WebSocket traffic to unaut... |
| CVE-2025-64308 | HIGH | 7.1 | 0.2% | Nov 15, 2025 | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Bri... |
| CVE-2025-64307 | HIGH | 7.1 | 0.2% | Nov 15, 2025 | The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized... |
| CVE-2025-62765 | HIGH | 8.7 | 0.3% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an a... |
| CVE-2025-59780 | HIGH | 8.7 | 0.3% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could all... |
| CVE-2025-58083 | CRITICAL | 10 | 0.6% | Nov 15, 2025 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could al... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now