2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62934 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mejar WP Business Hours wp-business-hours allows Stored XSS.This issu... |
| CVE-2025-62933 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Prakash Awesome Testimonials awesome-testimonials allows Stored XSS.T... |
| CVE-2025-62896 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in digitaldonkey Multilang Contact Form multilang-contact-form allows St... |
| CVE-2025-62886 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wpdevart Pricing Table builder wpdevart-pricing-table allows Stored X... |
| CVE-2025-12201 | HIGH | 7.2 | 0.5% | Oct 27, 2025 | A vulnerability was identified in ajayrandhawa User-Management-PHP-MYSQL up to fedcf58797bf2791591606f7b61fdad99ad8bff1.... |
| CVE-2025-11989 | HIGH | 8.1 | 0.2% | Oct 27, 2025 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18... |
| CVE-2025-11447 | HIGH | 7.5 | 0.8% | Oct 27, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.0 before 18.3.5, 18.4 before 18.4.3, and 1... |
| CVE-2025-10497 | HIGH | 7.5 | 0.6% | Oct 27, 2025 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.3.5, 18.4 before 18.4.3, and ... |
| CVE-2025-8709 | HIGH | 7.3 | 0.2% | Oct 26, 2025 | A SQL injection vulnerability exists in the langchain-ai/langchain repository, specifically in the LangGraph's SQLite st... |
| CVE-2025-12221 | HIGH | 8.8 | 0.2% | Oct 25, 2025 | Busybox 1.31.1 - Multiple Known Vulnerabilities.This issue affects BLU-IC2: through 1.19.5; BLU-IC4: through 1.19.5. |
| CVE-2025-9322 | HIGH | 7.5 | 0.3% | Oct 25, 2025 | The Stripe Payment Forms by WP Full Pay – Accept Credit Card Payments, Donations & Subscriptions plugin for WordPress is... |
| CVE-2025-8416 | HIGH | 7.5 | 0.4% | Oct 25, 2025 | The Product Filter by WBW plugin for WordPress is vulnerable to SQL Injection via the 'filtersDataBackend' parameter in ... |
| CVE-2025-4203 | HIGH | 7.5 | 0.3% | Oct 25, 2025 | The wpForo Forum plugin for WordPress is vulnerable to error‐based or time-based SQL Injection via the get_members() fun... |
| CVE-2025-10488 | HIGH | 8.1 | 0.8% | Oct 25, 2025 | The Directorist: AI-Powered Business Directory Plugin with Classified Ads Listings plugin for WordPress is vulnerable to... |
| CVE-2025-12095 | HIGH | 8.8 | 0.2% | Oct 25, 2025 | The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions... |
| CVE-2025-11238 | HIGH | 7.2 | 0.2% | Oct 25, 2025 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions ... |
| CVE-2025-34503 | HIGH | 7 | 0.1% | Oct 24, 2025 | Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker ... |
| CVE-2025-34502 | HIGH | 7 | 0.2% | Oct 24, 2025 | Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. ... |
| CVE-2025-34500 | HIGH | 7 | 0.1% | Oct 24, 2025 | Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit... |
| CVE-2025-4106 | HIGH | 8.9 | 0.3% | Oct 24, 2025 | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable ... |
| CVE-2025-34293 | HIGH | 8.6 | 0.4% | Oct 24, 2025 | GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API... |
| CVE-2025-60954 | HIGH | 8.3 | 0.4% | Oct 24, 2025 | Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexit... |
| CVE-2025-62716 | HIGH | 8.1 | 0.3% | Oct 24, 2025 | Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_pa... |
| CVE-2025-60735 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function |
| CVE-2025-60731 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now