2025 CVE Vulnerabilities
45,138 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12674 | CRITICAL | 9.8 | 0.7% | Nov 5, 2025 | The KiotViet Sync plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in th... |
| CVE-2025-11749 | CRITICAL | 9.8 | 75.8% | Nov 5, 2025 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2025-12735 | CRITICAL | 9.8 | 2.2% | Nov 5, 2025 | The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressio... |
| CVE-2025-52910 | CRITICAL | 9.8 | 0.3% | Nov 4, 2025 | An issue was discovered in the GPU in Samsung Mobile Processor and Wearable Processor Exynos 1280, 2200, 1330, 1380, 148... |
| CVE-2025-47776 | CRITICAL | 9.1 | 0.3% | Nov 4, 2025 | Mantis Bug Tracker (MantisBT) is an open source issue tracker. Due to incorrect use of loose (==) instead of strict (===... |
| CVE-2025-12108 | CRITICAL | 9.3 | 0.4% | Nov 4, 2025 | The Survision LPR Camera system does not enforce password protection by default. This allows access to the configuration... |
| CVE-2025-61956 | CRITICAL | 9.8 | 0.7% | Nov 4, 2025 | Radiometrics VizAir is vulnerable to a lack of authentication mechanisms for critical functions, such as admin access an... |
| CVE-2025-61945 | CRITICAL | 9.8 | 0.8% | Nov 4, 2025 | Radiometrics VizAir is vulnerable to any remote attacker via access to the admin panel of the VizAir system without auth... |
| CVE-2025-54863 | CRITICAL | 9.8 | 0.6% | Nov 4, 2025 | Radiometrics VizAir is vulnerable to exposure of the system's REST API key through a publicly accessible configuration f... |
| CVE-2025-12682 | CRITICAL | 9.8 | 0.5% | Nov 4, 2025 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to mis... |
| CVE-2025-12493 | CRITICAL | 9.8 | 0.7% | Nov 4, 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution (formerly WooLentor) pl... |
| CVE-2025-12158 | CRITICAL | 9.8 | 0.4% | Nov 4, 2025 | The Simple User Capabilities plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability chec... |
| CVE-2025-11008 | CRITICAL | 9.8 | 0.4% | Nov 4, 2025 | The CE21 Suite plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including... |
| CVE-2025-11007 | CRITICAL | 9.8 | 0.4% | Nov 4, 2025 | The CE21 Suite plugin for WordPress is vulnerable to unauthorized plugin settings update due to a missing capability che... |
| CVE-2025-12642 | CRITICAL | 9.1 | 0.3% | Nov 3, 2025 | lighttpd1.4.80 incorrectly merged trailer fields into headers after http request parsing. This behavior can be exploited... |
| CVE-2025-12531 | CRITICAL | 9.1 | 0.8% | Nov 3, 2025 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to an XML external entity injection (XXE) atta... |
| CVE-2025-12463 | CRITICAL | 9.8 | 0.5% | Nov 3, 2025 | An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` paramet... |
| CVE-2025-11953 | CRITICAL | 9.8 | 61.9% | Nov 3, 2025 | The Metro Development Server, which is opened by the React Native Community CLI, binds to external interfaces by default... |
| CVE-2025-63453 | CRITICAL | 9.8 | 0.4% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/contact.php. |
| CVE-2025-63452 | CRITICAL | 9.4 | 0.4% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/forgot-pass.php. |
| CVE-2025-63451 | CRITICAL | 9.8 | 0.4% | Nov 3, 2025 | Car-Booking-System-PHP v.1.0 is vulnerable to SQL Injection in /carlux/sign-in.php. |
| CVE-2025-8900 | CRITICAL | 9.8 | 0.3% | Nov 3, 2025 | The Doccure Core plugin for WordPress is vulnerable to privilege escalation in versions up to, and excluding, 1.5.4. Thi... |
| CVE-2025-0987 | CRITICAL | 9.9 | 0.3% | Nov 3, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in CB Project Ltd. Co. CVLand allows Parameter Injection.... |
| CVE-2025-12622 | CRITICAL | 9.8 | 0.8% | Nov 3, 2025 | A vulnerability was determined in Tenda AC10 16.03.10.13. Affected by this vulnerability is the function formSysRunCmd o... |
| CVE-2025-12619 | CRITICAL | 9.8 | 0.7% | Nov 3, 2025 | A vulnerability was found in Tenda A15 15.13.07.13. Affected is the function fromSetWirelessRepeat of the file /goform/o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now