2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10132 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The Dhivehi Text plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dhivehi' shortcode ... |
| CVE-2025-10056 | MEDIUM | 4.4 | 0.2% | Oct 15, 2025 | The Task Scheduler plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2025-10045 | MEDIUM | 4.9 | 0.3% | Oct 15, 2025 | The onOffice for WP-Websites plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versio... |
| CVE-2025-10038 | MEDIUM | 6.5 | 0.3% | Oct 15, 2025 | The Binary MLM Plan plugin for WordPress is vulnerable to limited Privilege Escalation in all versions up to, and includ... |
| CVE-2025-55039 | MEDIUM | 6.5 | 0.2% | Oct 15, 2025 | This issue affects Apache Spark versions before 3.4.4, 3.5.2 and 4.0.0. Apache Spark versions before 4.0.0, 3.5.2 an... |
| CVE-2025-11161 | MEDIUM | 5.4 | 0.2% | Oct 15, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the vc_custom_heading sh... |
| CVE-2025-11160 | MEDIUM | 5.4 | 0.2% | Oct 15, 2025 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Custom JS module in ... |
| CVE-2025-8561 | MEDIUM | 6.4 | 0.2% | Oct 15, 2025 | The Ova Advent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all vers... |
| CVE-2025-31702 | MEDIUM | 6.8 | 0.3% | Oct 15, 2025 | A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user cred... |
| CVE-2025-11176 | MEDIUM | 4.3 | 0.2% | Oct 15, 2025 | The Quick Featured Images plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, ... |
| CVE-2025-10406 | MEDIUM | 5.5 | 0.2% | Oct 15, 2025 | The BlindMatrix e-Commerce WordPress plugin before 3.1 does not validate some shortcode attributes before using them to ... |
| CVE-2025-55079 | MEDIUM | 5.5 | 0.2% | Oct 15, 2025 | In Eclipse ThreadX before version 6.4.3, the thread module has a setting of maximum priority. In some cases the check of... |
| CVE-2025-54278 | MEDIUM | 5.5 | 0.2% | Oct 15, 2025 | Bridge versions 14.1.8, 15.1.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to... |
| CVE-2025-54270 | MEDIUM | 5.5 | 0.2% | Oct 15, 2025 | Animate versions 23.0.13, 24.0.10 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead t... |
| CVE-2025-54269 | MEDIUM | 5.5 | 0.2% | Oct 15, 2025 | Animate versions 23.0.13, 24.0.10 and earlier are affected by an out-of-bounds read vulnerability that could lead to mem... |
| CVE-2025-61797 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha... |
| CVE-2025-61796 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha... |
| CVE-2025-54272 | MEDIUM | 5.4 | 0.2% | Oct 14, 2025 | Adobe Experience Manager versions 11.6 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability tha... |
| CVE-2025-54196 | MEDIUM | 4.3 | 0.3% | Oct 14, 2025 | Adobe Connect versions 12.9 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerabil... |
| CVE-2025-54267 | MEDIUM | 6.5 | 0.4% | Oct 14, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an... |
| CVE-2025-54266 | MEDIUM | 4.8 | 0.2% | Oct 14, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by a ... |
| CVE-2025-54265 | MEDIUM | 5.9 | 0.5% | Oct 14, 2025 | Adobe Commerce versions 2.4.9-alpha2, 2.4.8-p2, 2.4.7-p7, 2.4.6-p12, 2.4.5-p14, 2.4.4-p15 and earlier are affected by an... |
| CVE-2025-62374 | MEDIUM | 6.4 | 0.4% | Oct 14, 2025 | Parse Javascript SDK provides access to the powerful Parse Server backend from your JavaScript app. Prior to 7.0.0, inje... |
| CVE-2025-60540 | MEDIUM | 6.5 | 0.3% | Oct 14, 2025 | karakeep v0.26.0 to v0.7.0 was discovered to contain a Server-Side Request Forgery (SSRF). |
| CVE-2025-60374 | MEDIUM | 6.1 | 0.3% | Oct 14, 2025 | Stored Cross-Site Scripting (XSS) in Perfex CRM chatbot before 3.3.1 allows attackers to inject arbitrary HTML/JavaScrip... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now