2025 CVE Vulnerabilities
45,152 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10165 | MEDIUM | 6.4 | 0.2% | Oct 3, 2025 | The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back'... |
| CVE-2025-10053 | MEDIUM | 4.4 | 0.2% | Oct 3, 2025 | The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings... |
| CVE-2025-0876 | MEDIUM | 4.1 | 0.2% | Oct 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi A... |
| CVE-2025-61599 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitte... |
| CVE-2025-61597 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored ... |
| CVE-2025-61589 | MEDIUM | 5.9 | 0.3% | Oct 3, 2025 | Cursor is a code editor built for programming with AI. In versions 1.6 and below, Mermaid (a to render diagrams) allows ... |
| CVE-2025-11241 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The Yoast SEO Premium plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions 25.7 to 25.9 due to ... |
| CVE-2025-61606 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an Open R... |
| CVE-2025-54088 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the c... |
| CVE-2025-56019 | MEDIUM | 6.5 | 0.3% | Oct 2, 2025 | An insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobil... |
| CVE-2025-60661 | MEDIUM | 5.3 | 0.4% | Oct 2, 2025 | Tenda AC18 V15.03.05.19 was discovered to contain a stack overflow via the cloneType parameter in the fromAdvSetMacMtuWa... |
| CVE-2025-59406 | MEDIUM | 6.2 | 0.2% | Oct 2, 2025 | The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow Li... |
| CVE-2025-34210 | MEDIUM | 5.5 | 0.1% | Oct 2, 2025 | Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application (VA/SaaS deployments) store a large number o... |
| CVE-2025-57305 | MEDIUM | 6.5 | 0.4% | Oct 2, 2025 | VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp. |
| CVE-2025-56162 | MEDIUM | 6.5 | 0.5% | Oct 2, 2025 | YOSHOP 2.0 suffers from an unauthenticated SQL injection in the goodsIds parameter of the /api/goods/listByIds endpoint.... |
| CVE-2025-56154 | MEDIUM | 6.1 | 0.3% | Oct 2, 2025 | htmly v3.0.8 is vulnerable to Cross Site Scripting (XSS) in the /author/:name endpoint of the affected application. The ... |
| CVE-2025-61096 | MEDIUM | 6.5 | 0.2% | Oct 2, 2025 | PHPGurukul Online Shopping Portal Project v2.1 is vulnerable to SQL Injection in /shopping/login.php via the fullname pa... |
| CVE-2025-61087 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | SourceCodester Pet Grooming Management Software 1.0 is vulnerable to Cross Site Scripting (XSS) via the Customer Name fi... |
| CVE-2025-60782 | MEDIUM | 5.4 | 0.2% | Oct 2, 2025 | PHP Education Manager v1.0 is vulnerable to Cross Site Scripting (XSS) stored Cross-Site Scripting (XSS) vulnerability i... |
| CVE-2025-59774 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59773 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59772 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59771 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59770 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
| CVE-2025-59769 | MEDIUM | 6.1 | 0.2% | Oct 2, 2025 | Cross-site scripting (XSS) vulnerability reflected in AndSoft's e-TMS v25.03. This vulnerability allows an attacker to e... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now