2025 CVE Vulnerabilities
45,203 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11918 | HIGH | 7.3 | 0.1% | Nov 14, 2025 | Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the... |
| CVE-2025-10018 | MEDIUM | 4.8 | 0.2% | Nov 14, 2025 | QuickCMS is vulnerable to multiple Stored XSS in language editor functionality (languages). Malicious attacker with admi... |
| CVE-2025-8855 | HIGH | 8.1 | 0.3% | Nov 14, 2025 | Authorization Bypass Through User-Controlled Key, Weak Password Recovery Mechanism for Forgotten Password, Authenticatio... |
| CVE-2025-11981 | MEDIUM | 4.9 | 0.3% | Nov 14, 2025 | The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'SCodes' parame... |
| CVE-2025-11794 | MEDIUM | 4.9 | 0.2% | Nov 14, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to sanitize user data which allows sy... |
| CVE-2025-55073 | MEDIUM | 5.3 | 0.2% | Nov 14, 2025 | Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between ... |
| CVE-2025-55070 | HIGH | 7.5 | 0.3% | Nov 14, 2025 | Mattermost versions <11 fail to enforce multi-factor authentication on WebSocket connections which allows unauthenticate... |
| CVE-2025-41436 | MEDIUM | 4.3 | 0.1% | Nov 14, 2025 | Mattermost versions <11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regu... |
| CVE-2025-11776 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Mattermost versions <11 fail to properly restrict access to archived channel search API which allows guest users to disc... |
| CVE-2025-64444 | HIGH | 8.6 | 1.1% | Nov 14, 2025 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in NCP-HG100 1.4... |
| CVE-2025-10686 | HIGH | 7.2 | 0.4% | Nov 14, 2025 | The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possib... |
| CVE-2025-13161 | HIGH | 8.7 | 0.5% | Nov 14, 2025 | IQ-Support developed by IQ Service International has an Arbitrary File Read vulnerability, allowing unauthenticated remo... |
| CVE-2025-13160 | MEDIUM | 6.9 | 0.3% | Nov 14, 2025 | IQ-Support developed by IQ Service International has a Exposure of Sensitive Information vulnerability, allowing unauthe... |
| CVE-2025-9479 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Out of bounds read in V8 in Google Chrome prior to 133.0.6943.141 allowed a remote attacker to potentially exploit heap ... |
| CVE-2025-13107 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in Compositing in Google Chrome prior to 140.0.7339.80 allowed a remote attacker to perform... |
| CVE-2025-13102 | MEDIUM | 4.3 | 0.2% | Nov 14, 2025 | Inappropriate implementation in WebApp Installs in Google Chrome on Android prior to 134.0.6998.35 allowed a remote atta... |
| CVE-2025-13097 | MEDIUM | 5.4 | 0.1% | Nov 14, 2025 | Inappropriate implementation in DevTools in Google Chrome prior to 136.0.7103.59 allowed a remote attacker to potentiall... |
| CVE-2025-12904 | HIGH | 7.2 | 0.2% | Nov 14, 2025 | The SNORDIAN's H5PxAPIkatchu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'insert_data' AJA... |
| CVE-2025-64530 | HIGH | 7.5 | 0.3% | Nov 13, 2025 | Apollo Federation is an architecture for declaratively composing APIs into a unified graph. A vulnerability in versions ... |
| CVE-2025-64754 | LOW | 2.7 | 0.4% | Nov 13, 2025 | Jitsi Meet is an open source video conferencing application. A vulnerability present in versions prior to 2.0.10532 allo... |
| CVE-2025-64753 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document c... |
| CVE-2025-64752 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist instal... |
| CVE-2025-64749 | MEDIUM | 4.3 | 0.3% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. An observable difference in error messa... |
| CVE-2025-64748 | MEDIUM | 6.5 | 0.2% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. A vulnerability in versions prior to 11... |
| CVE-2025-64747 | MEDIUM | 5.5 | 0.2% | Nov 13, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. A stored cross-site scripting (XSS) vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now