2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-63710 | MEDIUM | 6.5 | 0.1% | Nov 10, 2025 | The send_message.php endpoint in SourceCodester Simple Public Chat Room 1.0 is vulnerable to Cross-Site Request Forgery ... |
| CVE-2025-63709 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Simple To-Do List System 1.0 in the "Add Tasks" text... |
| CVE-2025-41001 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | Cross Site Scripting (XSS) vulnerability stored in SOPlanning v1.53.02, which consist of a stored XSS due to a lack of p... |
| CVE-2025-41107 | MEDIUM | 5.4 | 0.2% | Nov 10, 2025 | Stored Cross Site Scripting (XSS) vulnerability in Smart School 7.0 due to lack of proper validation of user input when ... |
| CVE-2025-12924 | MEDIUM | 6.5 | 0.3% | Nov 10, 2025 | A vulnerability was identified in rymcu forest up to de53ce79db9faa2efc4e79ce1077a302c42a1224. This issue affects the fu... |
| CVE-2025-12923 | MEDIUM | 4.9 | 0.5% | Nov 10, 2025 | A vulnerability was determined in liweiyi ChestnutCMS up to 1.5.8. This vulnerability affects the function resourceDownl... |
| CVE-2025-12920 | MEDIUM | 4.8 | 0.3% | Nov 9, 2025 | A flaw has been found in qianfox FoxCMS up to 1.2.16. Affected by this vulnerability is the function add/edit of the fil... |
| CVE-2025-12918 | MEDIUM | 5.3 | 0.3% | Nov 9, 2025 | A security flaw has been discovered in yungifez Skuul School Management System up to 2.6.5. The impacted element is an u... |
| CVE-2025-12917 | MEDIUM | 4.3 | 0.5% | Nov 9, 2025 | A vulnerability was identified in TOZED ZLT T10 T10PLUS_3.04.15. The affected element is an unknown function of the file... |
| CVE-2025-12915 | MEDIUM | 6.4 | 0.4% | Nov 8, 2025 | A vulnerability was found in 70mai X200 up to 20251019. This issue affects some unknown processing of the component Init... |
| CVE-2025-12914 | MEDIUM | 4.7 | 0.2% | Nov 8, 2025 | A vulnerability has been found in aaPanel BaoTa up to 11.2.x. This vulnerability affects unknown code of the file /datab... |
| CVE-2025-12837 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Call To Actio... |
| CVE-2025-12643 | MEDIUM | 6.4 | 0.2% | Nov 8, 2025 | The Saphali LiqPay for donate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'saphali_liqpay'... |
| CVE-2025-12092 | MEDIUM | 6.5 | 0.6% | Nov 8, 2025 | The CYAN Backup plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation i... |
| CVE-2025-11980 | MEDIUM | 4.9 | 0.3% | Nov 8, 2025 | The Quick Featured Images plugin for WordPress is vulnerable to SQL Injection via the 'delete_orphaned' function in all ... |
| CVE-2025-11448 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The Gallery Plugin for WordPress – Envira Photo Gallery plugin for WordPress is vulnerable to unauthorized modification ... |
| CVE-2025-12098 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Sensitive I... |
| CVE-2025-12621 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Flexible Refund and Return Order for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of ... |
| CVE-2025-12498 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The EventPrime – Events Calendar, Bookings and Tickets plugin for WordPress is vulnerable to unauthorized booking note c... |
| CVE-2025-7663 | MEDIUM | 6.5 | 0.2% | Nov 8, 2025 | The Ovatheme Events Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check ... |
| CVE-2025-12353 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The WPFunnels – The Easiest Funnel Builder For WordPress And WooCommerce To Collect Leads And Increase Sales plugin for ... |
| CVE-2025-12193 | MEDIUM | 6.1 | 0.2% | Nov 8, 2025 | The Mang Board WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mp' parameter in all ver... |
| CVE-2025-12177 | MEDIUM | 5.3 | 0.2% | Nov 8, 2025 | The Download Manager plugin for WordPress is vulnerable to unauthorized access due to a hardcoded Cron key used in the d... |
| CVE-2025-12167 | MEDIUM | 4.3 | 0.2% | Nov 8, 2025 | The Contact Form 7 AWeber Extension plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-12125 | MEDIUM | 4.4 | 0.2% | Nov 8, 2025 | The HTML Forms – Simple WordPress Forms Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via adm... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now