2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12859 | HIGH | 7.2 | 0.3% | Nov 7, 2025 | A vulnerability has been found in DedeBIZ up to 6.3.2. This impacts an unknown function of the file /admin/templets_one_... |
| CVE-2025-34299 | CRITICAL | 9.8 | 72.5% | Nov 7, 2025 | Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This fl... |
| CVE-2025-12857 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A security vulnerability has been detected in code-projects Responsive Hotel Site 1.0. The affected element is an unknow... |
| CVE-2025-12856 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A weakness has been identified in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /... |
| CVE-2025-12855 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A security flaw has been discovered in code-projects Responsive Hotel Site 1.0. This issue affects some unknown processi... |
| CVE-2025-12854 | LOW | 3.7 | 0.4% | Nov 7, 2025 | A vulnerability was identified in newbee-mall-plus up to 2.4.1. This vulnerability affects the function executeSeckill o... |
| CVE-2025-12853 | CRITICAL | 9.8 | 0.3% | Nov 7, 2025 | A vulnerability was determined in SourceCodester Best House Rental Management System 1.0. This affects the function dele... |
| CVE-2025-10968 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'), CWE - 564 - SQL Injection: Hiberna... |
| CVE-2025-10870 | CRITICAL | 9.3 | 0.2% | Nov 7, 2025 | SQL injection vulnerability in DIAL's CentrosNet v2.64. Allows an attacker to retrieve, create, update, and delete datab... |
| CVE-2025-46413 | MEDIUM | 5.3 | 0.1% | Nov 7, 2025 | Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. W... |
| CVE-2025-10966 | MEDIUM | 4.3 | 0.4% | Nov 7, 2025 | curl's code for managing SSH connections when SFTP was done using the wolfSSH powered backend was flawed and missed host... |
| CVE-2025-64346 | MEDIUM | 6 | 0.3% | Nov 7, 2025 | archives is a Go library for extracting archives (tar, zip, etc.). Version 1.0.0 does not prevent a malicious user to fe... |
| CVE-2025-64343 | HIGH | 7.8 | 0.1% | Nov 7, 2025 | (conda) Constructor is a tool that enables users to create installers for conda package collections. In versions 3.12.2 ... |
| CVE-2025-64339 | MEDIUM | 5.4 | 0.2% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Playlists feature i... |
| CVE-2025-12527 | MEDIUM | 4.3 | 0.2% | Nov 7, 2025 | The Page & Post Notes plugin for WordPress is vulnerable to unauthorized modification of notes due to a missing capabili... |
| CVE-2025-12520 | MEDIUM | 4 | 0.2% | Nov 7, 2025 | The WP Airbnb Review Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all ... |
| CVE-2025-64338 | CRITICAL | 9 | 0.4% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2 - #156 and below, an authenticated regular use... |
| CVE-2025-64336 | MEDIUM | 5.4 | 0.3% | Nov 7, 2025 | ClipBucket v5 is an open source video sharing platform. In versions 5.5.2-#146 and below, the Manage Photos feature is v... |
| CVE-2025-64329 | MEDIUM | 5.5 | 0.2% | Nov 7, 2025 | containerd is an open-source container runtime. Versions 1.7.28 and below, 2.0.0-beta.0 through 2.0.6, 2.1.0-beta.0 thro... |
| CVE-2025-4522 | MEDIUM | 6.5 | 0.2% | Nov 7, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct ... |
| CVE-2025-4519 | HIGH | 8.8 | 0.3% | Nov 7, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escala... |
| CVE-2025-12352 | CRITICAL | 9.8 | 0.7% | Nov 7, 2025 | The Gravity Forms plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-64328 | HIGH | 7.2 | 84.4% | Nov 7, 2025 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and abov... |
| CVE-2025-64323 | MEDIUM | 5.3 | 0.2% | Nov 7, 2025 | kgateway is a Cloud-Native API and AI Gateway. Versions 2.0.4 and below and 2.1.0-agw-cel-rbac through 2.1.0-rc.2 lack a... |
| CVE-2025-64187 | MEDIUM | 4.4 | 0.1% | Nov 7, 2025 | OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now