2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-61430 | MEDIUM | 6.5 | 0.2% | Oct 24, 2025 | Improper handling of DNS over TCP in Simple DNS Plus v9 allows a remote attacker with querying access to the DNS server ... |
| CVE-2025-60936 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | Emoncms 11.7.3 is vulnerable to Cross Site in the input handling mechanism. This vulnerability allows authenticated atta... |
| CVE-2025-56438 | MEDIUM | 6.8 | 0.1% | Oct 24, 2025 | An issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically... |
| CVE-2025-46425 | MEDIUM | 6.5 | 0.3% | Oct 24, 2025 | Dell Storage Center - Dell Storage Manager, version(s) 20.1.20, contain(s) an Improper Restriction of XML External Entit... |
| CVE-2025-46185 | MEDIUM | 6.2 | 0.1% | Oct 24, 2025 | An Insecure Permission vulnerability in pgcodekeeper 10.12.0 allows a local attacker to obtain sensitive information via... |
| CVE-2025-11576 | MEDIUM | 4.3 | 0.3% | Oct 24, 2025 | The AI Chatbot Free Models – Customer Support, Live Chat, Virtual Assistant plugin for WordPress is vulnerable to CSV In... |
| CVE-2025-5605 | MEDIUM | 5.3 | 0.8% | Oct 24, 2025 | An authentication bypass vulnerability exists in the Management Console of multiple WSO2 products. A malicious actor wit... |
| CVE-2025-5350 | MEDIUM | 4.8 | 0.6% | Oct 24, 2025 | SSRF and Reflected XSS Vulnerabilities exist in multiple WSO2 products within the deprecated Try-It feature, which was a... |
| CVE-2025-12136 | MEDIUM | 6.8 | 0.4% | Oct 24, 2025 | The Real Cookie Banner: GDPR & ePrivacy Cookie Consent plugin for WordPress is vulnerable to Server-Side Request Forgery... |
| CVE-2025-12134 | MEDIUM | 5.3 | 0.2% | Oct 24, 2025 | The ZoloBlocks – Gutenberg Block Editor Plugin with Advanced Blocks, Dynamic Content, Templates & Patterns plugin for Wo... |
| CVE-2025-12096 | MEDIUM | 6.4 | 0.2% | Oct 24, 2025 | The Simple Excel Pricelist for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pr... |
| CVE-2025-12072 | MEDIUM | 4.3 | 0.1% | Oct 24, 2025 | The Disable Content Editor For Specific Template plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-12017 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | The VNPAY Payment gateway plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' paramet... |
| CVE-2025-12016 | MEDIUM | 4.4 | 0.2% | Oct 24, 2025 | The qnotsquiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'qnotsquiz_custom_start_text' pa... |
| CVE-2025-12014 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The NGINX Cache Optimizer plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-11992 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | The Multi Item Responsive Slider plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-11887 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check... |
| CVE-2025-11257 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The LLM Hubspot Blog Import plugin for WordPress is vulnerable to unauthorized modification of data due to a missing cap... |
| CVE-2025-11172 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Check Plagiarism plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability... |
| CVE-2025-10902 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capabilit... |
| CVE-2025-10901 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2025-10749 | MEDIUM | 5.4 | 0.2% | Oct 24, 2025 | The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in... |
| CVE-2025-10748 | MEDIUM | 6.5 | 0.3% | Oct 24, 2025 | The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc... |
| CVE-2025-10740 | MEDIUM | 6.3 | 0.2% | Oct 24, 2025 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid... |
| CVE-2025-10701 | MEDIUM | 6.4 | 0.2% | Oct 24, 2025 | The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now