2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49903 | MEDIUM | 5.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in bdthemes ZoloBlocks zoloblocks allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-49899 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in jjlemstra Whydonate wp-whydonate allows Accessing Functionality Not Properly Cons... |
| CVE-2025-49377 | MEDIUM | 6.3 | 0.2% | Oct 22, 2025 | Missing Authorization vulnerability in Themefic Hydra Booking hydra-booking allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-49376 | MEDIUM | 5.3 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Accessing Functionality Not Properly Const... |
| CVE-2025-49374 | MEDIUM | 5.4 | 0.2% | Oct 22, 2025 | Server-Side Request Forgery (SSRF) vulnerability in captcha.eu Captcha.eu captcha-eu allows Server Side Request Forgery.... |
| CVE-2025-49373 | MEDIUM | 4.3 | 0.1% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Evergreen Content Poster Evergreen Content Poster evergreen-content-p... |
| CVE-2025-48099 | MEDIUM | 4.7 | 0.2% | Oct 22, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Code Amp Search & Filter search-filter allows Cross Site Request Forg... |
| CVE-2025-48096 | MEDIUM | 6.5 | 0.3% | Oct 22, 2025 | Missing Authorization vulnerability in FRESHFACE Custom CSS custom-css-editor allows Exploiting Incorrectly Configured A... |
| CVE-2025-48095 | MEDIUM | 5.9 | 0.3% | Oct 22, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ays Pro Survey Mak... |
| CVE-2025-11966 | MEDIUM | 6.4 | 0.3% | Oct 22, 2025 | In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], when "directory listing" is enabled, file and directory n... |
| CVE-2025-8848 | MEDIUM | 5.4 | 0.4% | Oct 22, 2025 | A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a ... |
| CVE-2025-11844 | MEDIUM | 5.4 | 0.3% | Oct 22, 2025 | Hugging Face Smolagents version 1.20.0 contains an XPath injection vulnerability in the search_item_ctrl_f function loca... |
| CVE-2025-11750 | MEDIUM | 5.3 | 0.7% | Oct 22, 2025 | In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning d... |
| CVE-2025-11411 | MEDIUM | 5.7 | 0.3% | Oct 22, 2025 | NLnet Labs Unbound up to and including version 1.24.1 is vulnerable to possible domain hijack attacks. Promiscuous NS RR... |
| CVE-2025-6833 | MEDIUM | 4.3 | 0.2% | Oct 22, 2025 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Inse... |
| CVE-2025-11915 | MEDIUM | 6.9 | 0.3% | Oct 22, 2025 | Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in f... |
| CVE-2025-41109 | MEDIUM | 4.6 | 0.6% | Oct 22, 2025 | Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. T... |
| CVE-2025-11952 | MEDIUM | 6.1 | 0.2% | Oct 22, 2025 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co... |
| CVE-2025-11883 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Responsive Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rprogress... |
| CVE-2025-11880 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The SM CountDown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's smcountdown s... |
| CVE-2025-11878 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categorie... |
| CVE-2025-11872 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2025-11870 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' sh... |
| CVE-2025-11867 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta,... |
| CVE-2025-11866 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode att... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now