2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57839 | MEDIUM | 4 | 0.2% | Oct 20, 2025 | Photo module is affected by information leak vulnerability, successful exploitation of this vulnerability may affect ser... |
| CVE-2025-57838 | MEDIUM | 4 | 0.2% | Oct 20, 2025 | Some Honor products are affected by information leak vulnerability, successful exploitation of this vulnerability may af... |
| CVE-2025-11947 | MEDIUM | 4.5 | 0.2% | Oct 19, 2025 | A weakness has been identified in bftpd up to 6.2. Impacted is the function expand_groups of the file options.c of the c... |
| CVE-2025-11946 | MEDIUM | 5.4 | 0.3% | Oct 19, 2025 | A security flaw has been discovered in LogicalDOC Community Edition up to 9.2.1. This issue affects some unknown process... |
| CVE-2025-62672 | MEDIUM | 5.3 | 0.6% | Oct 19, 2025 | rplay through 3.3.2 allows attackers to cause a denial of service (SIGSEGV and daemon crash) or possibly have unspecifie... |
| CVE-2025-11926 | MEDIUM | 4.4 | 0.3% | Oct 18, 2025 | The Related Posts Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2025-11256 | MEDIUM | 5.3 | 0.3% | Oct 18, 2025 | The Kognetiks Chatbot plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capabilit... |
| CVE-2025-10750 | MEDIUM | 5.3 | 0.4% | Oct 18, 2025 | The PowerBI Embed Reports plugin for WordPress is vulnerable to Sensitive Information Disclosure in all versions up to, ... |
| CVE-2025-9562 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's qs... |
| CVE-2025-11741 | MEDIUM | 5.3 | 0.3% | Oct 18, 2025 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up t... |
| CVE-2025-11703 | MEDIUM | 5.3 | 0.2% | Oct 18, 2025 | The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Cache Poisoning in all versions up to, an... |
| CVE-2025-11519 | MEDIUM | 4.3 | 0.3% | Oct 18, 2025 | The Optimole – Optimize Images | Convert WebP & AVIF | CDN & Lazy Load | Image Optimization plugin for WordPress is vuln... |
| CVE-2025-11510 | MEDIUM | 4.3 | 0.2% | Oct 18, 2025 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2025-11372 | MEDIUM | 6.5 | 0.4% | Oct 18, 2025 | The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to modification of data in all versions up to, ... |
| CVE-2025-11270 | MEDIUM | 6.4 | 0.2% | Oct 18, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stor... |
| CVE-2025-10187 | MEDIUM | 4.9 | 0.4% | Oct 18, 2025 | The GSpeech TTS – WordPress Text To Speech Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' pa... |
| CVE-2025-10006 | MEDIUM | 5.4 | 0.2% | Oct 18, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rev_slider... |
| CVE-2025-11937 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11857 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The XX2WP Integration Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mxp_fb2wp_display... |
| CVE-2025-11742 | MEDIUM | 4.3 | 0.3% | Oct 18, 2025 | The WPC Smart Wishlist for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missin... |
| CVE-2025-11738 | MEDIUM | 5.3 | 0.4% | Oct 18, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to limited file reading in all versions up to, and includ... |
| CVE-2025-62671 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62670 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62669 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in The Wikimedia Foundation Mediawiki - Central... |
| CVE-2025-62668 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Incorrect Default Permissions vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows R... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now