2025 CVE Vulnerabilities
45,320 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-13023 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Sandbox escape due to incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in F... |
| CVE-2025-13022 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-13021 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 145 and Thunder... |
| CVE-2025-8324 | CRITICAL | 9.8 | 1.5% | Nov 11, 2025 | Zohocorp ManageEngine Analytics Plus versions 6170 and below are vulnerable to Unauthenticated SQL Injection due to the ... |
| CVE-2025-12539 | CRITICAL | 10 | 0.9% | Nov 11, 2025 | The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up... |
| CVE-2025-12813 | CRITICAL | 9.8 | 0.7% | Nov 11, 2025 | The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i... |
| CVE-2025-11457 | CRITICAL | 9.8 | 0.3% | Nov 11, 2025 | The EasyCommerce – AI-Powered, Fast & Beautiful WordPress Ecommerce Plugin plugin for WordPress is vulnerable to Privile... |
| CVE-2025-11170 | CRITICAL | 9.8 | 0.7% | Nov 11, 2025 | The WP移行専用プラグイン for CPI plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation... |
| CVE-2025-42890 | CRITICAL | 10 | 0.6% | Nov 11, 2025 | SQL Anywhere Monitor (Non-GUI) baked credentials into the code,exposing the resources or functionality to unintended use... |
| CVE-2025-42887 | CRITICAL | 9.9 | 0.5% | Nov 11, 2025 | Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when cal... |
| CVE-2025-11892 | CRITICAL | 9.6 | 0.6% | Nov 10, 2025 | An improper neutralization of input vulnerability was identified in GitHub Enterprise Server that allows DOM-based cross... |
| CVE-2025-64513 | CRITICAL | 9.3 | 1.0% | Nov 10, 2025 | Milvus is an open-source vector database built for generative AI applications. An unauthenticated attacker can exploit a... |
| CVE-2025-12480 | CRITICAL | 9.1 | 90.4% | Nov 10, 2025 | Triofox versions prior to 16.7.10368.56560, are vulnerable to an Improper Access Control flaw that allows access to init... |
| CVE-2025-12939 | CRITICAL | 9.8 | 0.3% | Nov 10, 2025 | A security flaw has been discovered in SourceCodester Interview Management System up to 1.0. Affected by this issue is s... |
| CVE-2025-12938 | CRITICAL | 9.8 | 0.4% | Nov 10, 2025 | A vulnerability was identified in projectworlds Online Admission System 1.0. Affected by this vulnerability is an unknow... |
| CVE-2025-12933 | CRITICAL | 9.8 | 0.3% | Nov 10, 2025 | A vulnerability was identified in SourceCodester Baby Care System 1.0. This affects an unknown part of the file /updatew... |
| CVE-2025-12932 | CRITICAL | 9.8 | 0.3% | Nov 10, 2025 | A vulnerability was determined in SourceCodester Baby Care System 1.0. Affected by this issue is some unknown functional... |
| CVE-2025-12931 | CRITICAL | 9.8 | 0.3% | Nov 10, 2025 | A vulnerability was found in SourceCodester Food Ordering System 1.0. Affected by this vulnerability is an unknown funct... |
| CVE-2025-12930 | CRITICAL | 9.8 | 0.3% | Nov 10, 2025 | A vulnerability has been found in SourceCodester Food Ordering System 1.0. Affected is an unknown function of the file /... |
| CVE-2025-12929 | CRITICAL | 9.8 | 0.4% | Nov 10, 2025 | A flaw has been found in SourceCodester Survey Application System 1.0. This impacts the function save_user/update_user o... |
| CVE-2025-12928 | CRITICAL | 9.8 | 0.4% | Nov 10, 2025 | A vulnerability was detected in code-projects Online Job Search Engine 1.0. This affects an unknown function of the file... |
| CVE-2025-12868 | CRITICAL | 9.8 | 0.5% | Nov 10, 2025 | New Site Server developed by CyberTutor has a Use of Client-Side Authentication vulnerability, allowing unauthenticated ... |
| CVE-2025-12866 | CRITICAL | 9.8 | 0.5% | Nov 10, 2025 | EIP Plus developed by Hundred Plus has a Weak Password Recovery Mechanism vulnerability, allowing unauthenticated remote... |
| CVE-2025-12925 | CRITICAL | 9.8 | 0.4% | Nov 10, 2025 | A security flaw has been discovered in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. Impacted is the func... |
| CVE-2025-12916 | CRITICAL | 9.8 | 4.7% | Nov 9, 2025 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unkno... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now