2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12203 | MEDIUM | 4.9 | 0.4% | Oct 27, 2025 | A weakness has been identified in givanz Vvveb up to 1.0.7.3. This issue affects the function sanitizeFileName of the fi... |
| CVE-2025-62988 | MEDIUM | 4.9 | 0.1% | Oct 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Reques... |
| CVE-2025-62987 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builder... |
| CVE-2025-62985 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in llamaman Simple Pu... |
| CVE-2025-62984 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter ... |
| CVE-2025-62983 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sudar Muthu Posts ... |
| CVE-2025-62982 | MEDIUM | 5.9 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Giles Dynami... |
| CVE-2025-62981 | MEDIUM | 4.7 | 0.2% | Oct 27, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zo... |
| CVE-2025-62980 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in MDZ Persian Admnin Fonts persian-admin-fonts allows Exploiting Incorrectly Config... |
| CVE-2025-62979 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in airesvsg ACF to REST API acf-to-rest-api allows Retri... |
| CVE-2025-62978 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Kiotviet KiotViet Sync kiotvietsync allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-62977 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in 沃之涛 百度站长SEO合集(支持百度/神马/Bing/头条推送) baiduseo allows Accessing Functionality Not Prop... |
| CVE-2025-62976 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Accessing Functiona... |
| CVE-2025-62975 | MEDIUM | 4.3 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in raychat Raychat raychat allows Cross Site Request Forgery.This issue ... |
| CVE-2025-62974 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoSchedule Headlin... |
| CVE-2025-62973 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Cons... |
| CVE-2025-62972 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Confi... |
| CVE-2025-62971 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Atte... |
| CVE-2025-62970 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Spencer Haws Link Whisper Free link-whisper allows Exploiting Incorrectly Configu... |
| CVE-2025-62969 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove... |
| CVE-2025-62968 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta WP Las... |
| CVE-2025-62967 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento Dire... |
| CVE-2025-62966 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Apiki GoCache gocache-cdn allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-62965 | MEDIUM | 5.5 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in wpseek Admin Management Xtended admin-management-xtended allows Exploiting Incor... |
| CVE-2025-62964 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Exploiting Incorre... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now