2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10869 | MEDIUM | 6.1 | 0.2% | Oct 15, 2025 | Stored Cross-site Scripting (XSS) in Oct8ne Chatbot v2.3. This vulnerability allows an attacker to execute JavaScript co... |
| CVE-2025-55082 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read i... |
| CVE-2025-11728 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Oceanpayment CreditCard Gateway plugin for WordPress is vulnerable to unauthenticated and unauthorized modification ... |
| CVE-2025-11701 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check ... |
| CVE-2025-11692 | MEDIUM | 5.3 | 0.2% | Oct 15, 2025 | The Zip Attachments plugin for WordPress is vulnerable to unauthorized loss of data due to a missing authorization and c... |
| CVE-2025-11365 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP Google Map Plugin plugin for WordPress is vulnerable to blind SQL Injection via the 'id' parameter of the 'google... |
| CVE-2025-11196 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The External Login plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and inclu... |
| CVE-2025-10730 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The Wp tabber widget plugin for WordPress is vulnerable to SQL Injection via the 'wp-tabber-widget' shortcode in all ver... |
| CVE-2025-10682 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The TARIFFUXX plugin for WordPress is vulnerable to SQL Injection in versions up to, and including, 1.4. This is due to ... |
| CVE-2025-10660 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP Dashboard Chat plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, ... |
| CVE-2025-10648 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The YourMembership Single Sign On – YM SSO Login plugin for WordPress is vulnerable to unauthorized access of data due t... |
| CVE-2025-10575 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The WP jQuery Pager plugin for WordPress is vulnerable to SQL Injection via the 'ids' shortcode attribute parameter hand... |
| CVE-2025-10486 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The Content Writer plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inclu... |
| CVE-2025-10312 | MEDIUM | 4.3 | 0.1% | Oct 15, 2025 | The Theme Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-10310 | MEDIUM | 4.9 | 0.3% | Oct 15, 2025 | The Rich Snippet Site Report plugin for WordPress is vulnerable to SQL Injection via the 'last' parameter in all versio... |
| CVE-2025-10303 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The Library Management System plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2025-10301 | MEDIUM | 4.3 | 0.1% | Oct 15, 2025 | The FunKItools plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2025-10300 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The TopBar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.0.... |
| CVE-2025-10194 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The Shortcode Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'button' shortco... |
| CVE-2025-10186 | MEDIUM | 5.3 | 0.3% | Oct 15, 2025 | The WhyDonate – FREE Donate button – Crowdfunding – Fundraising plugin for WordPress is vulnerable to unauthorized loss ... |
| CVE-2025-10141 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The Digiseller plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ds' shortcode in all ... |
| CVE-2025-10140 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The Quick Social Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'quick-login' ... |
| CVE-2025-10139 | MEDIUM | 6.4 | 0.3% | Oct 15, 2025 | The WP BookWidgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bw_link' shortcod... |
| CVE-2025-10135 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The WP ViewSTL plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'viewstl' shortcode in... |
| CVE-2025-10133 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The URLYar URL Shortner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'urlyar_short... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now