2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62667 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62666 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in The Wikimedia Foundation Mediawiki - CirrusSearch ... |
| CVE-2025-62664 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62663 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62662 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-11361 | MEDIUM | 6.4 | 0.3% | Oct 18, 2025 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Serv... |
| CVE-2025-62665 | MEDIUM | 6.9 | 0.4% | Oct 18, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2025-11378 | MEDIUM | 5.4 | 0.3% | Oct 18, 2025 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to unauthorized... |
| CVE-2025-62652 | MEDIUM | 5.9 | 0.4% | Oct 17, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in The Wikimed... |
| CVE-2025-62651 | MEDIUM | 5.8 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 does not implement access control for th... |
| CVE-2025-62649 | MEDIUM | 5.8 | 0.5% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 relies on client-side authentication for... |
| CVE-2025-62648 | MEDIUM | 5.8 | 0.4% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 allows remote attackers to adjust Drive ... |
| CVE-2025-62647 | MEDIUM | 5.8 | 0.3% | Oct 17, 2025 | The Restaurant Brands International (RBI) assistant platform through 2025-09-06 provides the functionality of returning ... |
| CVE-2025-62508 | MEDIUM | 6.5 | 0.4% | Oct 17, 2025 | Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. Citizen from 3.3.0 to 3.9.0 are vulne... |
| CVE-2025-62511 | MEDIUM | 6.3 | 0.1% | Oct 17, 2025 | yt-grabber-tui is a C++ terminal user interface application for downloading YouTube content. yt-grabber-tui version 1.0 ... |
| CVE-2025-11925 | MEDIUM | 6.1 | 0.2% | Oct 17, 2025 | Incorrect Content-Type header in one of the APIs (`text/html` instead of `application/json`) replies may potentially all... |
| CVE-2025-11913 | MEDIUM | 6.5 | 0.8% | Oct 17, 2025 | A vulnerability has been found in Shenzhen Ruiming Technology Streamax Crocus 1.3.40. Affected by this vulnerability is ... |
| CVE-2025-56320 | MEDIUM | 5.4 | 0.4% | Oct 17, 2025 | CobbleStone Enterprise Contract Management Portal v.22.4.0 is vulnerable to Stored Cross-Site Scripting (XSS) in its cha... |
| CVE-2025-34281 | MEDIUM | 5.4 | 0.3% | Oct 17, 2025 | ThingsBoard in versions prior to v4.2.1 allows an authenticated user to upload malicious SVG images via the "Image Galle... |
| CVE-2025-62430 | MEDIUM | 5.4 | 0.2% | Oct 17, 2025 | ClipBucket v5 is an open source video sharing platform. ClipBucket v5 through build 5.5.2 #145 allows stored cross-site ... |
| CVE-2025-62424 | MEDIUM | 6.5 | 0.9% | Oct 17, 2025 | ClipBucket is a web-based video-sharing platform. In ClipBucket version 5.5.2 - #146 and earlier, the /admin_area/templa... |
| CVE-2025-62421 | MEDIUM | 5.4 | 0.3% | Oct 17, 2025 | DataEase is a data visualization and analytics platform. In DataEase versions through 2.10.13, a stored cross-site scrip... |
| CVE-2025-60514 | MEDIUM | 6.5 | 0.3% | Oct 17, 2025 | Tillywork v0.1.3 and below is vulnerable to SQL Injection in app/common/helpers/query.builder.helper.ts. |
| CVE-2025-57164 | MEDIUM | 6.5 | 0.6% | Oct 17, 2025 | Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase ... |
| CVE-2025-58747 | MEDIUM | 6.1 | 5.2% | Oct 17, 2025 | Dify is an LLM application development platform. In Dify versions through 1.9.1, the MCP OAuth component is vulnerable t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now