2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12357 | MEDIUM | 6.3 | 0.2% | Oct 31, 2025 | By manipulating the Signal Level Attenuation Characterization (SLAC) protocol with spoofed measurements, an attacker ca... |
| CVE-2025-64387 | MEDIUM | 5.1 | 0.4% | Oct 31, 2025 | The web application is vulnerable to a so-called ‘clickjacking’ attack. In this type of attack, the vulnerable page is i... |
| CVE-2025-61427 | MEDIUM | 6.1 | 0.2% | Oct 31, 2025 | A reflected cross-site scripting (XSS) vulnerability in BEO GmbH BEO Atlas Einfuhr Ausfuhr 3.0 allows attackers to execu... |
| CVE-2025-12521 | MEDIUM | 5.3 | 0.2% | Oct 31, 2025 | The Analytify Pro plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includ... |
| CVE-2025-12460 | MEDIUM | 5.3 | 0.4% | Oct 31, 2025 | An XSS issue was discovered in Afterlogic Aurora webmail version 9.8.3 and below. An attacker can send a specially craft... |
| CVE-2025-4952 | MEDIUM | 6.8 | 0.1% | Oct 31, 2025 | Tampering of the registry entries might have led to preventing the ESET security products from starting correctly on the... |
| CVE-2025-36249 | MEDIUM | 5.3 | 0.1% | Oct 31, 2025 | IBM Jazz for Service Management 1.1.3.0 through 1.1.3.25 does not set the secure attribute on authorization tokens or se... |
| CVE-2025-64368 | MEDIUM | 5.4 | 0.1% | Oct 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mikado-Themes Bard bardwp allows Cross Site Request Forgery.This issu... |
| CVE-2025-64367 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adrian Tobey Groun... |
| CVE-2025-64365 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in colabrio Ohio Extr... |
| CVE-2025-64362 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SeventhQueen K Ele... |
| CVE-2025-64361 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in StylemixThemes Con... |
| CVE-2025-64358 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce wt-smart-coupons-for-woocommerce allows E... |
| CVE-2025-64357 | MEDIUM | 4.3 | 0.1% | Oct 31, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Younes JFR. Advanced Database Cleaner advanced-database-cleaner allow... |
| CVE-2025-64356 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Missing Authorization vulnerability in f1logic Insert PHP Code Snippet insert-php-code-snippet allows Exploiting Incorre... |
| CVE-2025-64354 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Matias Ventura Gut... |
| CVE-2025-64351 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows R... |
| CVE-2025-40603 | MEDIUM | 4.5 | 0.4% | Oct 31, 2025 | A potential exposure of sensitive information in log files in SonicWall SMA100 Series appliances may allow a remote, aut... |
| CVE-2025-11602 | MEDIUM | 6.3 | 0.3% | Oct 31, 2025 | Potential information leak in bolt protocol handshake in Neo4j Enterprise and Community editions allows attacker to obta... |
| CVE-2025-12041 | MEDIUM | 5.3 | 0.2% | Oct 31, 2025 | The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check... |
| CVE-2025-8383 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4.... |
| CVE-2025-30191 | MEDIUM | 5.4 | 0.2% | Oct 31, 2025 | Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended act... |
| CVE-2025-12175 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t... |
| CVE-2025-12094 | MEDIUM | 5.3 | 0.3% | Oct 31, 2025 | The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to... |
| CVE-2025-8385 | MEDIUM | 6.8 | 0.4% | Oct 31, 2025 | The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now