2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64459 | CRITICAL | 9.1 | 19.1% | Nov 5, 2025 | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. The methods `QuerySet.filter()`, ... |
| CVE-2025-64458 | HIGH | 7.5 | 1.9% | Nov 5, 2025 | An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is s... |
| CVE-2025-61084 | HIGH | 7.1 | 0.2% | Nov 5, 2025 | MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: h... |
| CVE-2025-52602 | MEDIUM | 4.2 | 0.1% | Nov 5, 2025 | HCL BigFix Query is affected by a sensitive information disclosure in the WebUI Query application. An HTTP GET endpoint... |
| CVE-2025-47151 | CRITICAL | 9.8 | 0.8% | Nov 5, 2025 | A type confusion vulnerability exists in the lasso_node_impl_init_from_xml functionality of Entr'ouvert Lasso 2.5.1 ... |
| CVE-2025-46784 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_node_init_from_message_with_format functionality of Entr'ouver... |
| CVE-2025-46705 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the g_assert_not_reached functionality of Entr'ouvert Lasso 2.5.1 and 2.... |
| CVE-2025-46404 | HIGH | 7.5 | 0.4% | Nov 5, 2025 | A denial of service vulnerability exists in the lasso_provider_verify_saml_signature functionality of Entr'ouvert La... |
| CVE-2025-3125 | HIGH | 7.2 | 0.8% | Nov 5, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper input validation in the CarbonAp... |
| CVE-2025-12497 | HIGH | 8.1 | 0.5% | Nov 5, 2025 | The Premium Portfolio Features for Phlox theme plugin for WordPress is vulnerable to Local File Inclusion in all version... |
| CVE-2025-11745 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom ... |
| CVE-2025-58337 | MEDIUM | 5.4 | 0.3% | Nov 5, 2025 | An attacker with a valid read-only account can bypass Doris MCP Server’s read-only mode due to improper access control, ... |
| CVE-2025-12469 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne... |
| CVE-2025-12468 | MEDIUM | 5.3 | 0.3% | Nov 5, 2025 | The FunnelKit Automations – Email Marketing Automation and CRM for WordPress & WooCommerce plugin for WordPress is vulne... |
| CVE-2025-12192 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The Events Calendar plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 6.15.... |
| CVE-2025-11987 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Visual Link Preview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's visual-link-p... |
| CVE-2025-11820 | MEDIUM | 6.4 | 0.2% | Nov 5, 2025 | The Graphina – Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl... |
| CVE-2025-55108 | CRITICAL | 10 | 0.7% | Nov 5, 2025 | The Control-M/Agent is vulnerable to unauthenticated remote code execution, arbitrary file read and write and similar un... |
| CVE-2025-12677 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12676 | MEDIUM | 5.3 | 0.3% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to authorizarion bypass in all versions up to, and including, 1.8.5... |
| CVE-2025-12675 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ch... |
| CVE-2025-12674 | CRITICAL | 9.8 | 0.7% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-10622 | HIGH | 8 | 0.5% | Nov 5, 2025 | A flaw was found in Red Hat Satellite (Foreman component). This vulnerability allows an authenticated user with edit_set... |
| CVE-2025-64151 | HIGH | 8.4 | 0.1% | Nov 5, 2025 | Multiple Roboticsware products provided by Roboticsware PTE. LTD. register Windows services with unquoted file paths. A ... |
| CVE-2025-62225 | HIGH | 8.4 | 0.1% | Nov 5, 2025 | Optical Disc Archive Software provided by Sony Corporation registers a Windows service with an unquoted file path. A use... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now