2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11536 | MEDIUM | 5 | 0.2% | Oct 20, 2025 | The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver... |
| CVE-2025-62657 | MEDIUM | 5.8 | 0.2% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62656 | MEDIUM | 5.8 | 0.2% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-60783 | MEDIUM | 6.5 | 0.2% | Oct 20, 2025 | There is a SQL injection vulnerability in Restaurant Management System DBMS Project v1.0 via login.php. The vulnerabilit... |
| CVE-2025-60781 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) in the worksheet.php file via the participant_nam... |
| CVE-2025-8051 | MEDIUM | 6.5 | 0.4% | Oct 20, 2025 | Path Traversal vulnerability in opentext Flipper allows Absolute Path Traversal. The vulnerability could allow a user ... |
| CVE-2025-8048 | MEDIUM | 6.5 | 0.3% | Oct 20, 2025 | External Control of File Name or Path vulnerability in opentext Flipper allows Path Traversal. The vulnerability could a... |
| CVE-2025-62528 | MEDIUM | 5.4 | 0.2% | Oct 20, 2025 | Taguette is an open source qualitative research tool. An issue has been discovered in Taguette versions prior to 1.5.0. ... |
| CVE-2025-62522 | MEDIUM | 6 | 1.0% | Oct 20, 2025 | Vite is a frontend tooling framework for JavaScript. In versions from 2.9.18 to before 3.0.0, 3.2.9 to before 4.0.0, 4.5... |
| CVE-2025-5517 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | Heap-based Buffer Overflow vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC ... |
| CVE-2025-62700 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62698 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62693 | MEDIUM | 6.9 | 0.3% | Oct 20, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11979 | MEDIUM | 6.5 | 0.2% | Oct 20, 2025 | An authorized user may crash the MongoDB server by causing buffer over-read. This can be done by issuing a DDL operation... |
| CVE-2025-6515 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | The MCP SSE endpoint in oatpp-mcp returns an instance pointer as the session ID, which is not unique nor cryptographical... |
| CVE-2025-60856 | MEDIUM | 6.8 | 0.3% | Oct 20, 2025 | Reolink Video Doorbell WiFi DB_566128M5MP_W allows root shell access through an unsecured UART/serial console. An attack... |
| CVE-2025-48025 | MEDIUM | 4.3 | 0.3% | Oct 20, 2025 | In Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000,... |
| CVE-2025-40005 | MEDIUM | 5.5 | 0.2% | Oct 20, 2025 | In the Linux kernel, the following vulnerability has been resolved: spi: cadence-quadspi: Implement refcount to handle ... |
| CVE-2025-8884 | MEDIUM | 5.5 | 0.2% | Oct 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in VHS Electronic Software Ltd. Co. ACE Center allows Pri... |
| CVE-2025-61456 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the index endpoin... |
| CVE-2025-11680 | MEDIUM | 5.9 | 0.4% | Oct 20, 2025 | Out-of-bounds Write in unfilter_scanline in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled during ... |
| CVE-2025-11679 | MEDIUM | 5.9 | 0.4% | Oct 20, 2025 | Out-of-bounds Read in lws_upng_emit_next_line in warmcat libwebsockets allows, when the LWS_WITH_UPNG flag is enabled du... |
| CVE-2025-11677 | MEDIUM | 6.3 | 0.4% | Oct 20, 2025 | Use After Free in WebSocket server implementation in lws_handshake_server in warmcat libwebsockets may allow an attacker... |
| CVE-2025-61454 | MEDIUM | 6.1 | 0.2% | Oct 20, 2025 | A Cross-Site Scripting (XSS) vulnerability exists in Bhabishya-123 E-commerce 1.0, specifically within the search endpoi... |
| CVE-2025-8349 | MEDIUM | 5.3 | 0.5% | Oct 20, 2025 | Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute Java... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now