2025 CVE Vulnerabilities
45,326 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9496 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file_modifie... |
| CVE-2025-9196 | MEDIUM | 5.3 | 1.0% | Oct 11, 2025 | The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to S... |
| CVE-2025-11197 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ... |
| CVE-2025-10185 | MEDIUM | 4.9 | 0.3% | Oct 11, 2025 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'orderb... |
| CVE-2025-10048 | MEDIUM | 4.9 | 0.3% | Oct 11, 2025 | The My auctions allegro plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter in all versions up... |
| CVE-2025-58285 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the media module. Successful exploitation of this vulnerability may affect service c... |
| CVE-2025-58284 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the network module. Successful exploitation of this vulnerability may affect service... |
| CVE-2025-58283 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the Wi-Fi module. Successful exploitation of this vulnerability may affect service c... |
| CVE-2025-58282 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the camera module. Successful exploitation of this vulnerability may affect service ... |
| CVE-2025-58278 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Identity authentication bypass vulnerability in the Gallery app. Successful exploitation of this vulnerability may affec... |
| CVE-2025-58277 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission verification bypass vulnerability in the Camera app. Successful exploitation of this vulnerability may affect... |
| CVE-2025-9560 | MEDIUM | 6.4 | 0.2% | Oct 11, 2025 | The Colibri Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's colibri_news... |
| CVE-2025-11380 | MEDIUM | 5.9 | 0.4% | Oct 11, 2025 | The Everest Backup – WordPress Cloud Backup, Migration, Restore & Cloning Plugin plugin for WordPress is vulnerable to u... |
| CVE-2025-54654 | MEDIUM | 5.5 | 0.1% | Oct 11, 2025 | Permission control vulnerability in the Gallery module. Successful exploitation of this vulnerability may affect service... |
| CVE-2025-9554 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal Owl Carousel 2.This issue affects Owl Carousel 2: *.*. |
| CVE-2025-9553 | MEDIUM | 5.3 | 0.2% | Oct 10, 2025 | Vulnerability in Drupal API Key manager.This issue affects API Key manager: *.*. |
| CVE-2025-9552 | MEDIUM | 5.3 | 0.3% | Oct 10, 2025 | Vulnerability in Drupal Synchronize composer.Json With Contrib Modules.This issue affects Synchronize composer.Json With... |
| CVE-2025-9551 | MEDIUM | 6.5 | 0.4% | Oct 10, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Drupal Protected Pages allows Brute Force.Thi... |
| CVE-2025-9550 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal Facets allo... |
| CVE-2025-9549 | MEDIUM | 6.5 | 0.2% | Oct 10, 2025 | Missing Authorization vulnerability in Drupal Facets allows Forceful Browsing.This issue affects Facets: from 0.0.0 befo... |
| CVE-2025-52885 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | Poppler ia a library for rendering PDF files, and examining or modifying their structure. A use-after-free (write) vulne... |
| CVE-2025-52647 | MEDIUM | 6.1 | 0.2% | Oct 10, 2025 | The BigFix WebUI application responds with HOST information from the HTTP header field making it vulnerable to Host Head... |
| CVE-2025-11626 | MEDIUM | 5.5 | 0.1% | Oct 10, 2025 | MONGO dissector infinite loop in Wireshark 4.4.0 to 4.4.9 and 4.2.0 to 4.2.13 allows denial of service |
| CVE-2025-61912 | MEDIUM | 5.3 | 0.4% | Oct 10, 2025 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, ldap.dn... |
| CVE-2025-61911 | MEDIUM | 6.5 | 0.3% | Oct 10, 2025 | python-ldap is a lightweight directory access protocol (LDAP) client API for Python. In versions prior to 3.4.5, the san... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now