2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12101 | MEDIUM | 5.9 | 24.6% | Nov 11, 2025 | Cross-Site Scripting (XSS) in NetScaler ADC and NetScaler Gateway when the appliance is configured as a Gateway (VPN vir... |
| CVE-2025-11862 | HIGH | 8.4 | 0.3% | Nov 11, 2025 | A security issue was discovered within Verve Asset Manager allowing unauthorized read-only users to read, update, and de... |
| CVE-2025-11697 | HIGH | 8.9 | 0.1% | Nov 11, 2025 | A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability a... |
| CVE-2025-11696 | HIGH | 8.9 | 0.1% | Nov 11, 2025 | A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. ... |
| CVE-2025-11085 | HIGH | 8.6 | 0.3% | Nov 11, 2025 | A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in t... |
| CVE-2025-11084 | HIGH | 7.6 | 0.1% | Nov 11, 2025 | A security issue exists within DataMosaix™ Private Cloud, allowing attackers to bypass MFA during setup and obtain a val... |
| CVE-2025-8324 | CRITICAL | 9.8 | 1.5% | Nov 11, 2025 | Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the ... |
| CVE-2025-41106 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41105 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41104 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41103 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-10161 | HIGH | 7.3 | 0.2% | Nov 11, 2025 | Improper Restriction of Excessive Authentication Attempts, Client-Side Enforcement of Server-Side Security, Reliance on ... |
| CVE-2025-41102 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-41101 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | HTML injection vulnerability found in Fairsketch's RISE CRM Framework v3.8.1, which consist of an HTML code injection du... |
| CVE-2025-11960 | MEDIUM | 6.1 | 0.2% | Nov 11, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Aryom Softw... |
| CVE-2025-7633 | MEDIUM | 6.1 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-7632 | MEDIUM | 5.4 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-7430 | MEDIUM | 5.4 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-12953 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una... |
| CVE-2025-12846 | HIGH | 8.8 | 0.6% | Nov 11, 2025 | The Blocksy Companion plugin for WordPress is vulnerable to authenticated arbitrary file upload in all versions up to, a... |
| CVE-2025-12788 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to missing payment veri... |
| CVE-2025-12787 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Hydra Booking — Appointment Scheduling & Booking Calendar plugin for WordPress is vulnerable to unauthorized booking... |
| CVE-2025-12539 | CRITICAL | 10 | 0.9% | Nov 11, 2025 | The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2025-9524 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The VAPIX API port.cgi did not have sufficient input validation, which may result in process crashes and impact usabilit... |
| CVE-2025-9055 | MEDIUM | 6.4 | 0.1% | Nov 11, 2025 | The VAPIX Edge storage API that allowed a privilege escalation, enabling a VAPIX administrator-privileged user to gain L... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now