2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12158 | CRITICAL | 9.8 | 0.4% | Nov 4, 2025 | The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec... |
| CVE-2025-12157 | MEDIUM | 5.3 | 0.2% | Nov 4, 2025 | The Simple User Capabilities plugin for WordPress is vulnerable to unauthorized modification of data due to a missing ca... |
| CVE-2025-12156 | MEDIUM | 4.3 | 0.2% | Nov 4, 2025 | The Ai Auto Tool Content Writing Assistant (Gemini Writer, ChatGPT ) All in One plugin for WordPress is vulnerable to un... |
| CVE-2025-12065 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The WP Carticon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carticon_js_script' parameter... |
| CVE-2025-11890 | HIGH | 7.5 | 0.2% | Nov 4, 2025 | The Crypto Payment Gateway with Payeer for WooCommerce plugin for WordPress is vulnerable to payment bypass in all versi... |
| CVE-2025-11812 | MEDIUM | 6.4 | 0.2% | Nov 4, 2025 | The Reuse Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'reuse_builder_single_post_t... |
| CVE-2025-11758 | MEDIUM | 6.5 | 0.2% | Nov 4, 2025 | The All in One Time Clock Lite plugin for WordPress is vulnerable to unauthorized access due to a missing authorization ... |
| CVE-2025-11753 | MEDIUM | 4.4 | 0.2% | Nov 4, 2025 | The Bootstrap Multi-language Responsive Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2025-11733 | HIGH | 7.2 | 0.2% | Nov 4, 2025 | The Footnotes Made Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin settings in all ver... |
| CVE-2025-11724 | HIGH | 8.8 | 0.5% | Nov 4, 2025 | The EM Beer Manager plugin for WordPress is vulnerable to arbitrary file upload leading to remote code execution in all ... |
| CVE-2025-11704 | HIGH | 7.5 | 0.5% | Nov 4, 2025 | The Elegance Menu plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9 v... |
| CVE-2025-10896 | HIGH | 8.8 | 0.5% | Nov 4, 2025 | Multiple plugins for WordPress with the Jewel Theme Recommended Plugins Library are vulnerable to Unrestricted Upload of... |
| CVE-2025-47370 | MEDIUM | 6.5 | 0.1% | Nov 4, 2025 | Transient DOS when a remote device sends an invalid connection request during BT connectable LE scan. |
| CVE-2025-47368 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption when dereferencing an invalid userspace address in a user buffer during MCDM IOCTL processing. |
| CVE-2025-47367 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while accessing a buffer during IOCTL processing. |
| CVE-2025-47365 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while processing large input data from a remote source via a communication interface. |
| CVE-2025-47362 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | Information disclosure while processing message from client with invalid payload. |
| CVE-2025-47361 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption when triggering a subsystem crash with an out-of-range identifier. |
| CVE-2025-47360 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while processing client message during device management. |
| CVE-2025-47357 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Information Disclosure when a user-level driver performs QFPROM read or write operations on Fuse regions. |
| CVE-2025-47353 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while processing request sent from GVM. |
| CVE-2025-47352 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while processing audio streaming operations. |
| CVE-2025-27074 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while processing a GP command response. |
| CVE-2025-27070 | HIGH | 7.8 | 0.1% | Nov 4, 2025 | Memory corruption while performing encryption and decryption commands. |
| CVE-2025-27064 | MEDIUM | 6.1 | 0.1% | Nov 4, 2025 | Information disclosure while registering commands from clients with diag through diagHal. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now