2025 CVE Vulnerabilities
45,150 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11634 | MEDIUM | 4.6 | 0.2% | Oct 12, 2025 | A security flaw has been discovered in Tomofun Furbo 360 and Furbo Mini. This affects an unknown part of the component U... |
| CVE-2025-11633 | MEDIUM | 5.9 | 0.2% | Oct 12, 2025 | A vulnerability was identified in Tomofun Furbo 360 and Furbo Mini. Affected by this issue is the function upload_file_t... |
| CVE-2025-52615 | MEDIUM | 5.3 | 0.2% | Oct 12, 2025 | HCL Unica Platform is impacted by misconfigured security related HTTP headers. This can lead to less secure browser def... |
| CVE-2025-52614 | MEDIUM | 4.3 | 0.1% | Oct 12, 2025 | HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability. A malicious agent may be able to in... |
| CVE-2025-31969 | MEDIUM | 6.1 | 0.1% | Oct 12, 2025 | HCL Unica Platform is impacted by misconfigured Content Security Policy (CSP). These can result in malicious resources ... |
| CVE-2025-31992 | MEDIUM | 4.6 | 0.2% | Oct 12, 2025 | HCL Unica MaxAI Assistant is susceptible to a HTML injection vulnerability. An attacker could insert special characters... |
| CVE-2025-11628 | MEDIUM | 4.7 | 0.2% | Oct 12, 2025 | A flaw has been found in jimit105 Project-Online-Shopping-Website up to 7d892f442bd8a96dd242dbe2b9bd5ed641e13e64. This a... |
| CVE-2025-11606 | MEDIUM | 6.3 | 0.2% | Oct 11, 2025 | A security flaw has been discovered in iPynch Social Network Website up to b6933b6d7f82c84819abe458ccf0e59d61119541. The... |
| CVE-2025-9975 | MEDIUM | 6.8 | 0.3% | Oct 11, 2025 | The WP Scraper plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 5... |
| CVE-2025-9950 | MEDIUM | 4.9 | 0.7% | Oct 11, 2025 | The Error Log Viewer by BestWebSoft plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and... |
| CVE-2025-9947 | MEDIUM | 4.9 | 0.3% | Oct 11, 2025 | The Custom 404 Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ‘path’ parameter in all versio... |
| CVE-2025-9626 | MEDIUM | 4.3 | 0.2% | Oct 11, 2025 | The Page Blocks plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-9621 | MEDIUM | 4.3 | 0.1% | Oct 11, 2025 | The WidgetPack Comment System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an... |
| CVE-2025-8682 | MEDIUM | 4.3 | 0.2% | Oct 11, 2025 | The Newsup theme for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on th... |
| CVE-2025-8484 | MEDIUM | 5.3 | 0.3% | Oct 11, 2025 | The Code Quality Control Tool plugin for WordPress is vulnerable to Sensitive Information Exposure in version 2.1 throug... |
| CVE-2025-7652 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Easy Plugin Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eps' shortcode... |
| CVE-2025-58301 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ... |
| CVE-2025-58300 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Buffer overflow vulnerability in the device management module. Successful exploitation of this vulnerability may affect ... |
| CVE-2025-58293 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe... |
| CVE-2025-58289 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Vulnerability of improper exception handling in the print module. Successful exploitation of this vulnerability may affe... |
| CVE-2025-10376 | MEDIUM | 4.3 | 0.1% | Oct 11, 2025 | The Course Redirects for Learndash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-10375 | MEDIUM | 4.3 | 0.1% | Oct 11, 2025 | The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-10190 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The WP Easy Toggles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggles' shortco... |
| CVE-2025-10175 | MEDIUM | 6.5 | 0.4% | Oct 11, 2025 | The WP Links Page plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and ... |
| CVE-2025-10167 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Stock History & Reports Manager for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now