2025 CVE Vulnerabilities
45,325 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10901 | MEDIUM | 4.3 | 0.2% | Oct 24, 2025 | The Originality.ai AI Checker plugin for WordPress is vulnerable to unauthorized access of data due to a missing capabil... |
| CVE-2025-10749 | MEDIUM | 5.4 | 0.2% | Oct 24, 2025 | The Microsoft Azure Storage for WordPress plugin for WordPress is vulnerable to Unauthorized Arbitrary Media Deletion in... |
| CVE-2025-10748 | MEDIUM | 6.5 | 0.3% | Oct 24, 2025 | The RapidResult plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up to, and inc... |
| CVE-2025-10740 | MEDIUM | 6.3 | 0.2% | Oct 24, 2025 | The URL Shortener Plugin For WordPress plugin for WordPress is vulnerable to unauthorized access to functionality provid... |
| CVE-2025-10701 | MEDIUM | 6.4 | 0.2% | Oct 24, 2025 | The Time Clock – A WordPress Employee & Volunteer Time Clock Plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2025-9978 | MEDIUM | 6.8 | 0.3% | Oct 24, 2025 | The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.ph... |
| CVE-2025-9158 | MEDIUM | 5.3 | 0.4% | Oct 24, 2025 | The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which d... |
| CVE-2025-61931 | MEDIUM | 5.4 | 0.2% | Oct 24, 2025 | Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attac... |
| CVE-2025-58070 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to ... |
| CVE-2025-10874 | MEDIUM | 5.5 | 0.2% | Oct 24, 2025 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2... |
| CVE-2025-7730 | MEDIUM | 6.4 | 0.2% | Oct 23, 2025 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter i... |
| CVE-2025-60023 | MEDIUM | 6.3 | 0.5% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-59776 | MEDIUM | 6.3 | 0.5% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-62517 | MEDIUM | 5.9 | 0.4% | Oct 23, 2025 | Rollbar.js offers error tracking and logging from Javascript to Rollbar. In versions before 2.26.5 and from 3.0.0-alpha1... |
| CVE-2025-62236 | MEDIUM | 6.9 | 0.3% | Oct 23, 2025 | The Frontier Airlines website has a publicly available endpoint that validates if an email addresses is associated with ... |
| CVE-2025-57848 | MEDIUM | 6.4 | 0.2% | Oct 23, 2025 | A container privilege escalation flaw was found in certain Container-native Virtualization images. This issue stems from... |
| CVE-2025-54966 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. Some endpoints on the SOCET GXP Job Status Service may return s... |
| CVE-2025-54963 | MEDIUM | 6.5 | 0.6% | Oct 23, 2025 | An issue was discovered in BAE SOCET GXP before 4.6.0.2. An attacker with the ability to interact with the GXP Job Servi... |
| CVE-2025-62255 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Self Cross-site scripting (XSS) vulnerability on the edit Knowledge Base article page in Liferay Portal 7.4.0 through 7.... |
| CVE-2025-60859 | MEDIUM | 6.1 | 0.3% | Oct 23, 2025 | Cross Site Scripting (XSS) vulnerability in Gnuboard 5.6.15 allows authenticated attackers to execute arbitrary code via... |
| CVE-2025-60837 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | A reflected cross-site scripting (XSS) vulnerability in MCMS v6.0.1 allows attackers to execute arbitrary Javascript in ... |
| CVE-2025-23345 | MEDIUM | 4.4 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in a video decoder, where an attacker might cause a... |
| CVE-2025-23332 | MEDIUM | 5 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where an attacker might be able to trigger ... |
| CVE-2025-23330 | MEDIUM | 5.5 | 0.2% | Oct 23, 2025 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker might be able to trigger a null pointer deref... |
| CVE-2025-23300 | MEDIUM | 5.5 | 0.1% | Oct 23, 2025 | NVIDIA Display Driver for Linux contains a vulnerability in the kernel driver, where a user could cause a null pointer d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now