2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8383 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The Depicter plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions less than, or equal to, 4.0.4.... |
| CVE-2025-30191 | MEDIUM | 5.4 | 0.2% | Oct 31, 2025 | Malicious content from E-Mail can be used to perform a redressing attack. Users can be tricked to perform unintended act... |
| CVE-2025-12175 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The The Events Calendar plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on t... |
| CVE-2025-12094 | MEDIUM | 5.3 | 0.3% | Oct 31, 2025 | The OOPSpam Anti-Spam: Spam Protection for WordPress Forms & Comments (No CAPTCHA) plugin for WordPress is vulnerable to... |
| CVE-2025-8385 | MEDIUM | 6.8 | 0.4% | Oct 31, 2025 | The Zombify plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5. This is du... |
| CVE-2025-58152 | MEDIUM | 6.9 | 0.3% | Oct 31, 2025 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection i... |
| CVE-2025-11191 | MEDIUM | 5.3 | 0.3% | Oct 31, 2025 | The RealPress WordPress plugin before 1.1.0 registers the REST routes without proper permission checks, allowing the cr... |
| CVE-2025-11975 | MEDIUM | 4.3 | 0.2% | Oct 31, 2025 | The FuseWP – WordPress User Sync to Email List & Marketing Automation (Mailchimp, Constant Contact, ActiveCampaign etc.)... |
| CVE-2025-11806 | MEDIUM | 6.4 | 0.2% | Oct 31, 2025 | The Qzzr Shortcode Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qzzr' shortcode in all ver... |
| CVE-2025-48980 | MEDIUM | 6.5 | 0.3% | Oct 31, 2025 | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split Vie... |
| CVE-2025-27208 | MEDIUM | 6.1 | 1.4% | Oct 31, 2025 | A reflected Cross-Site Scripting (XSS) vulnerability has been identified in Revive Adserver version 5.5.2. An attacker c... |
| CVE-2025-34283 | MEDIUM | 6.5 | 1.0% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Nept... |
| CVE-2025-34278 | MEDIUM | 5.4 | 0.7% | Oct 30, 2025 | Nagios Network Analyzer versions prior to 2024R1 contain a stored cross-site scripting (XSS) vulnerability in the Source... |
| CVE-2025-34273 | MEDIUM | 6.5 | 0.9% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administ... |
| CVE-2025-34272 | MEDIUM | 6.5 | 0.8% | Oct 30, 2025 | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the applicatio... |
| CVE-2025-34270 | MEDIUM | 4.9 | 0.6% | Oct 30, 2025 | Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fa... |
| CVE-2025-34135 | MEDIUM | 4.4 | 0.3% | Oct 30, 2025 | Nagios XI versions prior to 2024R1.4.2 configure some systemd unit files with permission sets that were too permissive. ... |
| CVE-2025-62265 | MEDIUM | 5.4 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in the Blogs widget in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupp... |
| CVE-2025-57109 | MEDIUM | 6.5 | 0.3% | Oct 30, 2025 | Kitware VTK (Visualization Toolkit) 9.5.0 is vulnerable to Heap Use-After-Free in vtkGLTFImporter::ImportActors. When pr... |
| CVE-2025-52180 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Infinity 4.2 and earlier allows remote unauthenticated atta... |
| CVE-2025-52179 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Cross-site scripting (XSS) vulnerability in Zucchetti Ad Hoc Revolution 4.1 and earlier allows remote unauthenticated at... |
| CVE-2025-64118 | MEDIUM | 6.1 | 0.1% | Oct 30, 2025 | node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uni... |
| CVE-2025-64116 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts... |
| CVE-2025-64115 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use... |
| CVE-2025-62266 | MEDIUM | 6.1 | 0.2% | Oct 30, 2025 | By default, Liferay Portal 7.4.0 through 7.4.3.119, and older unsupported versions, and Liferay DXP 2024.Q1.1 through 20... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now