2025 CVE Vulnerabilities
45,146 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60116 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in ThemeGoods Grand Conference Theme Custom Post Type grandconference-custom-post al... |
| CVE-2025-60111 | HIGH | 8.8 | 0.2% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in javothemes Javo Core javo-core allows Authentication Bypass.This issu... |
| CVE-2025-60110 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup AllIn... |
| CVE-2025-60109 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe... |
| CVE-2025-60108 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe... |
| CVE-2025-60107 | HIGH | 8.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Lambe... |
| CVE-2025-59012 | HIGH | 7.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shinetheme Travele... |
| CVE-2025-59011 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | Missing Authorization vulnerability in shinetheme Traveler traveler allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2025-59010 | HIGH | 7.5 | 0.4% | Sep 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Maciej Bis Permalink Manager Lite permalink-manager a... |
| CVE-2025-59002 | HIGH | 7.7 | 0.4% | Sep 26, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in SeaTheme BM Content Buil... |
| CVE-2025-4957 | HIGH | 7.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileG... |
| CVE-2025-48107 | HIGH | 7.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in undsgn Uncode unco... |
| CVE-2025-1862 | HIGH | 7.2 | 0.5% | Sep 26, 2025 | An arbitrary file upload vulnerability exists in multiple WSO2 products due to improper validation of user-supplied file... |
| CVE-2025-11021 | HIGH | 7.5 | 0.6% | Sep 26, 2025 | A flaw was found in the cookie date handling logic of the libsoup HTTP library, widely used by GNOME and other applicati... |
| CVE-2025-10871 | HIGH | 7.2 | 0.4% | Sep 26, 2025 | An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 b... |
| CVE-2025-10858 | HIGH | 7.5 | 0.6% | Sep 26, 2025 | An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1... |
| CVE-2025-35027 | HIGH | 7.3 | 2.3% | Sep 26, 2025 | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a com... |
| CVE-2025-10747 | HIGH | 7.2 | 0.6% | Sep 26, 2025 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2025-10997 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A flaw has been found in Open Babel up to 3.1.1. Impacted is the function ChemKinFormat::CheckSpecies of the file /src/f... |
| CVE-2025-10996 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A vulnerability was detected in Open Babel up to 3.1.1. This issue affects the function OBSmilesParser::ParseSmiles of t... |
| CVE-2025-10995 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A security vulnerability has been detected in Open Babel up to 3.1.1. This vulnerability affects the function zlib_strea... |
| CVE-2025-10994 | HIGH | 7.8 | 0.2% | Sep 26, 2025 | A weakness has been identified in Open Babel up to 3.1.1. This affects the function GAMESSOutputFormat::ReadMolecule of ... |
| CVE-2025-10993 | HIGH | 7.2 | 0.4% | Sep 26, 2025 | A security flaw has been discovered in MuYuCMS up to 2.7. Affected by this issue is some unknown functionality of the fi... |
| CVE-2025-60017 | HIGH | 8.2 | 1.1% | Sep 26, 2025 | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 allow root OS command injection via the hostapd_restart.sh wifi_s... |
| CVE-2025-10989 | HIGH | 8.8 | 0.4% | Sep 26, 2025 | A security flaw has been discovered in yangzongzhuan RuoYi up to 4.8.1. This vulnerability affects unknown code of the f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now