2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-20731 | MEDIUM | 5.3 | 0.1% | Nov 4, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20730 | MEDIUM | 6.7 | 0.1% | Nov 4, 2025 | In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local esc... |
| CVE-2025-20729 | MEDIUM | 4.2 | 0.1% | Nov 4, 2025 | In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local es... |
| CVE-2025-20728 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | In wlan STA driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local e... |
| CVE-2025-20727 | HIGH | 8.1 | 0.5% | Nov 4, 2025 | In Modem, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote escalation of... |
| CVE-2025-20726 | HIGH | 7.5 | 0.4% | Nov 4, 2025 | In Modem, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote escalation... |
| CVE-2025-20725 | HIGH | 7.5 | 0.5% | Nov 4, 2025 | In ims service, there is a possible out of bounds write due to a missing bounds check. This could lead to remote escalat... |
| CVE-2025-12683 | MEDIUM | 5.8 | 0.1% | Nov 4, 2025 | The service employed by Everything, running as SYSTEM, communicates with the lower privileged Everything GUI via a named... |
| CVE-2025-12456 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Centangle-Team plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-12452 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Visit Counter plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missin... |
| CVE-2025-12416 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Pagerank Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Cross-Site Request Forgery in a... |
| CVE-2025-12415 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The MapMap plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. T... |
| CVE-2025-12413 | MEDIUM | 5.4 | 0.1% | Nov 4, 2025 | The Social Media WPCF7 Stop Words plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-12412 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Top Bar Notification plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-12410 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The SH Contextual Help plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-12403 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The Associados Amazon Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-12402 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The LinkedIn Resume plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-12400 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | The LMB^Box Smileys plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-12396 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The clubmember plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up t... |
| CVE-2025-12393 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The Free Quotation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions ... |
| CVE-2025-12389 | MEDIUM | 4.3 | 0.2% | Nov 4, 2025 | The Import Export For WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2025-12371 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The Nari Accountant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via account settings in all versio... |
| CVE-2025-12369 | MEDIUM | 6.4 | 0.2% | Nov 4, 2025 | The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `geojsonmarker`... |
| CVE-2025-12350 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | The DominoKit plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wp_ajax... |
| CVE-2025-12188 | MEDIUM | 4.3 | 0.1% | Nov 4, 2025 | The Posts Navigation Links for Sections and Headings – Free by WP Masters plugin for WordPress is vulnerable to Cross-Si... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now