2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8998 | LOW | 3.1 | 0.2% | Nov 11, 2025 | It was possible to upload files with a specific name to a temporary directory, which may result in process crashes and i... |
| CVE-2025-7429 | MEDIUM | 5.4 | 0.4% | Nov 11, 2025 | Zohocorp ManageEngine Exchange Reporter Plus versions 5723 and below are vulnerable to the Stored XSS Vulnerability in t... |
| CVE-2025-5317 | MEDIUM | 5.5 | 0.1% | Nov 11, 2025 | An improper access restriction to a folder in Bitdefender Endpoint Security Tools for Mac (BEST) before 7.20.52.200087 a... |
| CVE-2025-10714 | HIGH | 8.4 | 0.1% | Nov 11, 2025 | AXIS Optimizer was vulnerable to an unquoted search path vulnerability, which could potentially lead to privilege escala... |
| CVE-2025-8108 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file has improper permissions and lacks input validation, which could potentially lead to privileg... |
| CVE-2025-6779 | MEDIUM | 6.7 | 1.0% | Nov 11, 2025 | An ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privile... |
| CVE-2025-6571 | MEDIUM | 6 | 0.1% | Nov 11, 2025 | A 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it. |
| CVE-2025-6298 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | ACAP applications can gain elevated privileges due to improper input validation, potentially leading to privilege escala... |
| CVE-2025-5718 | MEDIUM | 6.8 | 0.3% | Nov 11, 2025 | The ACAP Application framework could allow privilege escalation through a symlink attack. This vulnerability can only be... |
| CVE-2025-5454 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow a path traversal attack leading to pote... |
| CVE-2025-5452 | MEDIUM | 6.6 | 0.3% | Nov 11, 2025 | A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applicat... |
| CVE-2025-4645 | MEDIUM | 6.7 | 0.1% | Nov 11, 2025 | An ACAP configuration file lacked sufficient input validation, which could allow for arbitrary code execution. This vuln... |
| CVE-2025-11855 | HIGH | 7.5 | 0.2% | Nov 11, 2025 | The age-restriction WordPress plugin through 3.0.2 does not have authorisation in the age_restrictionRemoteSupportReques... |
| CVE-2025-11307 | HIGH | 8.8 | 1.9% | Nov 11, 2025 | The WP Go Maps (formerly WP Google Maps) WordPress plugin before 9.0.48 does not sanitize user input provided via an AJA... |
| CVE-2025-11237 | MEDIUM | 5.3 | 0.3% | Nov 11, 2025 | The Make Email Customizer for WooCommerce WordPress plugin through 1.0.6 lacks proper authorization checks and option va... |
| CVE-2025-12880 | MEDIUM | 5.4 | 0.1% | Nov 11, 2025 | The Progress Bar Blocks for Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File upl... |
| CVE-2025-12813 | CRITICAL | 9.8 | 0.7% | Nov 11, 2025 | The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2025-12754 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Geopost plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'height' parameter of the 'geopost... |
| CVE-2025-12753 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Chart Expert plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pmzez_chart' shortcode in al... |
| CVE-2025-12711 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Share to Google Classroom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the share_to_google ... |
| CVE-2025-12672 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The Flickr Show plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'div_height' parameter of the ... |
| CVE-2025-12671 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP-Iconics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the 'wp_icon... |
| CVE-2025-12668 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The WP Count Down Timer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters of the... |
| CVE-2025-12667 | MEDIUM | 6.4 | 0.2% | Nov 11, 2025 | The GitHub Gist Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of th... |
| CVE-2025-12665 | MEDIUM | 4.3 | 0.2% | Nov 11, 2025 | The Ninja Countdown | Fastest Countdown Builder plugin for WordPress is vulnerable to unauthorized loss of data due to a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now