2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11915 | MEDIUM | 6.9 | 0.3% | Oct 22, 2025 | Connection desynchronization between an HTTP proxy and the model backend. The fixes were rolled out for all proxies in f... |
| CVE-2025-41109 | MEDIUM | 4.6 | 0.6% | Oct 22, 2025 | Ghost Robotics Vision 60 v0.27.2 includes, among its physical interfaces, three RJ45 connectors and a USB Type-C port. T... |
| CVE-2025-11952 | MEDIUM | 6.1 | 0.2% | Oct 22, 2025 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co... |
| CVE-2025-11883 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Responsive Progress Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's rprogress... |
| CVE-2025-11880 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The SM CountDown Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's smcountdown s... |
| CVE-2025-11878 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The ST Categories Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's st-categorie... |
| CVE-2025-11872 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Material Design Iconic Font Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pl... |
| CVE-2025-11870 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Simple Business Data plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'simple_business_data' sh... |
| CVE-2025-11867 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Bg Book Publisher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `book_author` post meta,... |
| CVE-2025-11866 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Photographers galleries plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode att... |
| CVE-2025-11834 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The WP AD Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'startindex' parameter of th... |
| CVE-2025-11830 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The WP Restaurant Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' parameter o... |
| CVE-2025-11827 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Oboxmedia Ads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_widget' and 'after_w... |
| CVE-2025-11825 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Playerzbr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'urlmeta' post meta field in all... |
| CVE-2025-11824 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Cinza Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cgrid_skin_content' post meta ... |
| CVE-2025-11819 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The WP-Thumbnail plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'roboshot' shortcode in all v... |
| CVE-2025-11818 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The WP Responsive Meet The Team plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wprm_team' sh... |
| CVE-2025-11817 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Simple Tableau Viz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tableau' shortcode in ... |
| CVE-2025-11813 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Responsive iframe GoogleMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'responsive_ma... |
| CVE-2025-11811 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Simple Youtube Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'embed_youtube' s... |
| CVE-2025-11810 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Print Button Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'print-button' shor... |
| CVE-2025-11809 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The WP-Force Images Download plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpfid' shortcode... |
| CVE-2025-11807 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The Mixlr Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mixlr' shortcode in all v... |
| CVE-2025-11804 | MEDIUM | 6.4 | 0.3% | Oct 22, 2025 | The JB News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' shortcode attribute of... |
| CVE-2025-10138 | MEDIUM | 6.4 | 0.2% | Oct 22, 2025 | The This-or-That plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'thisorthat' shortco... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now