2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11962 | HIGH | 7.3 | 0.2% | Nov 12, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in DivvyDrive ... |
| CVE-2025-64406 | MEDIUM | 4.3 | 0.4% | Nov 12, 2025 | An out-of-bounds Write vulnerability in Apache OpenOffice could allow an attacker to craft a document that would crash t... |
| CVE-2025-64405 | HIGH | 7.5 | 1.3% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-64404 | HIGH | 7.5 | 1.2% | Nov 12, 2025 | Apache OpenOffice documents can contain links to other files. A missing Authorization vulnerability in Apache OpenOffice... |
| CVE-2025-64403 | HIGH | 8.1 | 1.3% | Nov 12, 2025 | Apache OpenOffice Calc spreadsheet can contain links to other files, in the form of "external data sources". A missing A... |
| CVE-2025-64402 | MEDIUM | 6.5 | 0.5% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-64401 | HIGH | 7.5 | 0.8% | Nov 12, 2025 | Apache OpenOffice documents can contain links. A missing Authorization vulnerability in Apache OpenOffice allowed an att... |
| CVE-2025-12903 | HIGH | 7.5 | 0.4% | Nov 12, 2025 | The Payment Plugins Braintree For WooCommerce plugin for WordPress is vulnerable to authorization bypass due to a missin... |
| CVE-2025-12732 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of sen... |
| CVE-2025-13047 | — | — | — | Nov 12, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-13046 | — | — | — | Nov 12, 2025 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2025-12872 | MEDIUM | 5.4 | 0.2% | Nov 12, 2025 | The a+HRD and a+HCM developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote ... |
| CVE-2025-12871 | CRITICAL | 9.8 | 0.5% | Nov 12, 2025 | The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to c... |
| CVE-2025-12870 | CRITICAL | 9.8 | 0.6% | Nov 12, 2025 | The a+HRD developed by aEnrich has an Authentication Abuse vulnerability, allowing unauthenticated remote attackers to s... |
| CVE-2025-12869 | MEDIUM | 4.8 | 0.2% | Nov 12, 2025 | The a+HRD developed by aEnrich has a Stored Cross-Site Scripting vulnerability, allowing remote attackers with administr... |
| CVE-2025-12633 | HIGH | 7.5 | 0.2% | Nov 12, 2025 | The Booking Calendar | Appointment Booking | Bookit plugin for WordPress is vulnerable to unauthorized modification of d... |
| CVE-2025-12113 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The Alt Text Generator AI – Auto Generate & Bulk Update Alt Texts For Images plugin for WordPress is vulnerable to unaut... |
| CVE-2025-12018 | MEDIUM | 4.4 | 0.2% | Nov 12, 2025 | The MembershipWorks – Membership, Events & Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting v... |
| CVE-2025-11560 | HIGH | 7.1 | 0.1% | Nov 12, 2025 | The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it ba... |
| CVE-2025-12901 | MEDIUM | 4.3 | 0.1% | Nov 12, 2025 | The Asgaros Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-12833 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to ... |
| CVE-2025-12087 | MEDIUM | 4.3 | 0.2% | Nov 12, 2025 | The Wishlist and Save for later for Woocommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference i... |
| CVE-2025-54983 | MEDIUM | 5.2 | 0.1% | Nov 12, 2025 | A health check port on Zscaler Client Connector on Windows, versions 4.6 < 4.6.0.216 and 4.7 < 4.7.0.47, which under sp... |
| CVE-2025-40111 | HIGH | 7.8 | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix Use-after-free in validation Nodes... |
| CVE-2025-40110 | — | — | 0.2% | Nov 12, 2025 | In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix a null-ptr access in the cursor sno... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now