2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62698 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62693 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11979 | MEDIUM | 6.5 | 0.2% | Oct 20, 2025 | An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation... |
| CVE-2025-6515 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographical... |
| CVE-2025-60856 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack... |
| CVE-2025-48025 | MEDIUM | 4.3 | 0.3% | Oct 20, 2025 | In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,... |
| CVE-2025-40005 | MEDIUM | 5.5 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle ... |
| CVE-2025-8884 | MEDIUM | 5.5 | 0.2% | Oct 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri... |
| CVE-2025-61456 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoin... |
| CVE-2025-11680 | MEDIUM | 5.9 | 0.4% | Oct 20, 2025 | Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during ... |
| CVE-2025-11679 | MEDIUM | 5.9 | 0.4% | Oct 20, 2025 | Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled du... |
| CVE-2025-11677 | MEDIUM | 6.3 | 0.4% | Oct 20, 2025 | Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker... |
| CVE-2025-61454 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoi... |
| CVE-2025-8349 | MEDIUM | 5.3 | 0.5% | Oct 20, 2025 | Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute Java... |
| CVE-2025-57839 | MEDIUM | 4 | 0.2% | Oct 20, 2025 | Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect ser... |
| CVE-2025-57838 | MEDIUM | 4 | 0.2% | Oct 20, 2025 | Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may af... |
| CVE-2025-11947 | MEDIUM | 4.5 | 0.2% | Oct 19, 2025 | A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the c... |
| CVE-2025-11946 | MEDIUM | 5.4 | 0.3% | Oct 19, 2025 | A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process... |
| CVE-2025-62672 | MEDIUM | 5.3 | 0.5% | Oct 19, 2025 | rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecifie... |
| CVE-2025-11926 | MEDIUM | 4.4 | 0.3% | Oct 18, 2025 | The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2025-11256 | MEDIUM | 5.3 | 0.3% | Oct 18, 2025 | The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2025-10750 | MEDIUM | 5.3 | 0.4% | Oct 18, 2025 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, ... |
| CVE-2025-9562 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs... |
| CVE-2025-11741 | MEDIUM | 5.3 | 0.3% | Oct 18, 2025 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
| CVE-2025-11703 | MEDIUM | 5.3 | 0.2% | Oct 18, 2025 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, an... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now