2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64450 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-64449 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-64448 | — | — | — | Nov 5, 2025 | Rejected reason: Not used |
| CVE-2025-12580 | MEDIUM | 6.1 | 0.2% | Nov 5, 2025 | The SMS for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'paged' parameter in ... |
| CVE-2025-11835 | MEDIUM | 5.3 | 0.2% | Nov 5, 2025 | The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPres... |
| CVE-2025-8871 | MEDIUM | 5.6 | 0.2% | Nov 5, 2025 | The Everest Forms (Pro) plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,... |
| CVE-2025-12582 | MEDIUM | 4.3 | 0.2% | Nov 5, 2025 | The Features plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check o... |
| CVE-2025-12735 | CRITICAL | 9.8 | 2.2% | Nov 5, 2025 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio... |
| CVE-2025-64110 | HIGH | 7.5 | 0.3% | Nov 5, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.23 and below, a logic bug allows a malicious agen... |
| CVE-2025-64109 | HIGH | 8.8 | 0.4% | Nov 5, 2025 | Cursor is a code editor built for programming with AI. In versions and below, a vulnerability in the Cursor CLI Beta all... |
| CVE-2025-64108 | HIGH | 8.8 | 0.4% | Nov 4, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a pr... |
| CVE-2025-64107 | HIGH | 8.8 | 0.3% | Nov 4, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.52 and below, manipulating internal settings may ... |
| CVE-2025-64106 | HIGH | 8.8 | 0.3% | Nov 4, 2025 | Cursor is a code editor built for programming with AI. In versions 1.7.28 and below, an input validation flaw in Cursor'... |
| CVE-2025-62722 | MEDIUM | 5.4 | 0.2% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, the social media sharing functio... |
| CVE-2025-59596 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addr... |
| CVE-2025-59595 | HIGH | 7.5 | 0.3% | Nov 4, 2025 | CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12.... |
| CVE-2025-62721 | MEDIUM | 6.5 | 0.3% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. In versions 2.3.1 and below, authenticated RSS feed endpoints... |
| CVE-2025-62720 | MEDIUM | 6.5 | 0.3% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. Versions 2.3.1 and below allow any authenticated user to expo... |
| CVE-2025-62719 | MEDIUM | 4.3 | 0.3% | Nov 4, 2025 | LinkAce is a self-hosted archive to collect website links. In versions 2.3.0 and below, the htmlKeywordsFromUrl function... |
| CVE-2025-62715 | MEDIUM | 5.4 | 0.2% | Nov 4, 2025 | ClipBucket v5 is an open source video sharing platform. Versions 5.5.2-#147 and below contain a stored Cross-Site Script... |
| CVE-2025-62520 | MEDIUM | 4.3 | 0.2% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.27.1 and below, due to insufficient access-... |
| CVE-2025-62507 | HIGH | 8.8 | 6.4% | Nov 4, 2025 | Redis is an open source, in-memory database that persists on disk. In versions 8.2.0 and above, a user can run the XACKD... |
| CVE-2025-62369 | HIGH | 7.2 | 0.9% | Nov 4, 2025 | Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below con... |
| CVE-2025-56230 | HIGH | 7.5 | 0.2% | Nov 4, 2025 | Tencent Docs Desktop 3.9.20 and earlier suffers from Missing SSL Certificate Validation in the update component. |
| CVE-2025-54526 | HIGH | 8.4 | 0.2% | Nov 4, 2025 | Fuji Electric Monitouch V-SFT-6 is vulnerable to a stack-based buffer overflow while processing a specially crafted pro... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now