2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12180 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The Qi Blocks plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.3. T... |
| CVE-2025-12090 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Employee Spotlight – Team Member Showcase & Meet the Team Plugin plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-12038 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The Folderly plugin for WordPress is vulnerable to unauthorized modification of data due to an insufficient capability c... |
| CVE-2025-11983 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The WP Discourse plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5.9.... |
| CVE-2025-11740 | MEDIUM | 6.5 | 0.2% | Nov 1, 2025 | The wpForo Forum plugin for WordPress is vulnerable to SQL Injection via the Subscriptions Manager in all versions up to... |
| CVE-2025-11502 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Schema & Structured Data for WP & AMP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plug... |
| CVE-2025-12118 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions ... |
| CVE-2025-11927 | MEDIUM | 4.4 | 0.2% | Nov 1, 2025 | The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2025-11377 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,... |
| CVE-2025-12367 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin... |
| CVE-2025-11928 | MEDIUM | 4.4 | 0.2% | Nov 1, 2025 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-62275 | MEDIUM | 5.3 | 0.2% | Nov 1, 2025 | Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.... |
| CVE-2025-11922 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individ... |
| CVE-2025-11816 | MEDIUM | 5.3 | 0.2% | Nov 1, 2025 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul... |
| CVE-2025-11174 | MEDIUM | 5.3 | 0.3% | Nov 1, 2025 | The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and includ... |
| CVE-2025-62276 | MEDIUM | 5.5 | 0.1% | Nov 1, 2025 | The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver... |
| CVE-2025-12464 | MEDIUM | 6.2 | 0.2% | Oct 31, 2025 | A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped ... |
| CVE-2025-63563 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions... |
| CVE-2025-63562 | MEDIUM | 6.3 | 0.2% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorizati... |
| CVE-2025-60711 | MEDIUM | 6.3 | 0.4% | Oct 31, 2025 | Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a n... |
| CVE-2025-62267 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | Multiple cross-site scripting (XSS) vulnerabilities in web content template’s select structure page in Liferay Portal 7.... |
| CVE-2025-12546 | MEDIUM | 5.4 | 0.3% | Oct 31, 2025 | A vulnerability was determined in LogicalDOC Community Edition up to 9.2.1. This affects an unknown part of the componen... |
| CVE-2025-62264 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | Reflected cross-site scripting (XSS) vulnerability in Languauge Override in Liferay Portal 7.4.3.8 through 7.4.3.111, an... |
| CVE-2025-6075 | MEDIUM | 5.5 | 0.1% | Oct 31, 2025 | If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env... |
| CVE-2025-59501 | MEDIUM | 4.8 | 3.1% | Oct 31, 2025 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing o... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now