2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11956 | HIGH | 8.9 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Proliz Soft... |
| CVE-2025-10955 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Netcad Soft... |
| CVE-2025-11268 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Strong Testimonials plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and i... |
| CVE-2025-12360 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Better Find and Replace – AI-Powered Suggestions plugin for WordPress is vulnerable to unauthorized API usage due to... |
| CVE-2025-10259 | MEDIUM | 5.3 | 0.4% | Nov 6, 2025 | Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Co... |
| CVE-2025-12471 | MEDIUM | 6.1 | 0.2% | Nov 6, 2025 | The Hubbub Lite – Fast, free social sharing and follow buttons plugin for WordPress is vulnerable to Reflected Cross-Sit... |
| CVE-2025-9338 | HIGH | 7.3 | 0.1% | Nov 6, 2025 | A improper restriction of operations within the bounds of a memory buffer exists in AsIO3.sys driver. This vulnerability... |
| CVE-2025-12560 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in... |
| CVE-2025-61994 | MEDIUM | 5.4 | 0.1% | Nov 6, 2025 | Cross-site scripting vulnerability exists in GROWI prior to v7.2.10. If a malicious user creates a page containing craft... |
| CVE-2025-12563 | MEDIUM | 4.3 | 0.2% | Nov 6, 2025 | The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to limited file upload due to an ... |
| CVE-2025-11271 | MEDIUM | 5.3 | 0.3% | Nov 6, 2025 | The Easy Digital Downloads plugin for WordPress is vulnerable to Order Manipulation in all versions up to, and including... |
| CVE-2025-64480 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64479 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64478 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64477 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64476 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64475 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64474 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64473 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-64472 | — | — | — | Nov 6, 2025 | Rejected reason: Not used |
| CVE-2025-10691 | MEDIUM | 4.3 | 0.1% | Nov 6, 2025 | The Easy Email Subscription plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-10683 | MEDIUM | 4.9 | 0.2% | Nov 6, 2025 | The Easy Email Subscription plugin for WordPress is vulnerable to SQL Injection via the 'uid' parameter in all versions ... |
| CVE-2025-64171 | HIGH | 8.7 | 0.2% | Nov 6, 2025 | MARIN3R is a lightweight, CRD based envoy control plane for kubernetes. In versions 0.13.3 and below, there is a cross-n... |
| CVE-2025-64164 | CRITICAL | 9.8 | 0.5% | Nov 6, 2025 | Dataease is an open source data visualization analysis tool. In versions 2.10.14 and below, DataEase did not properly fi... |
| CVE-2025-64163 | CRITICAL | 9.8 | 1.0% | Nov 6, 2025 | DataEase is an open source data visualization analysis tool. In versions 2.10.14 and below, the vendor added a blacklist... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now