2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58853 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Popping Sidebars and Widgets Light popping-sidebars-and-wid... |
| CVE-2025-58852 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Mark O'Donnell MSTW League Manager mstw-league-manager allows Stored ... |
| CVE-2025-58849 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Deepak S Hide Real Download Path hide-real-download-path allows Store... |
| CVE-2025-58848 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in aakash1911 WP likes wp-likes allows Reflected XSS.This issue affects ... |
| CVE-2025-58847 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Yaidier WN Flipbox Pro wn-flipbox-pro allows Reflected XSS.This issue... |
| CVE-2025-58846 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dejan Markovic WordPress Buffer – HYPESocial. Social Media Auto Post,... |
| CVE-2025-58845 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ChrisHurst Bulk Watermark bulk-watermark allows Reflected XSS.This is... |
| CVE-2025-58844 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Subhash Kumar Database to Excel database-to-excel allows Stored XSS.T... |
| CVE-2025-58843 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in David Merinas Auto Last Youtube Video auto-last-youtube-video allows ... |
| CVE-2025-58839 | HIGH | 7.2 | 0.4% | Sep 5, 2025 | Deserialization of Untrusted Data vulnerability in aThemeArt Translations eDS Responsive Menu eds-responsive-menu allows... |
| CVE-2025-58833 | HIGH | 8.8 | 0.2% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in INVELITY Invelity MyGLS connect invelity-mygls-connect allows Object ... |
| CVE-2025-58815 | HIGH | 7.2 | 0.4% | Sep 5, 2025 | Deserialization of Untrusted Data vulnerability in Rubel Miah Aitasi Coming Soon aitasi-coming-soon allows Object Inject... |
| CVE-2025-58809 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Nick Ciske To Lead For Salesforce salesforce-wordpress-to-lead allows... |
| CVE-2025-58807 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Dsingh Purge Varnish Cache purge-varnish allows Stored XSS.This issue... |
| CVE-2025-58806 | HIGH | 7.1 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tom Longridge WordPress Error Monitoring by Bugsnag bugsnag allows St... |
| CVE-2025-58789 | HIGH | 7.6 | 0.3% | Sep 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeisle WP Full ... |
| CVE-2025-58788 | HIGH | 7.6 | 0.4% | Sep 5, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal License... |
| CVE-2025-10011 | HIGH | 8.8 | 0.5% | Sep 5, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. The affected element is an unknown function of the fil... |
| CVE-2025-58400 | HIGH | 8.4 | 0.2% | Sep 5, 2025 | RATOC RAID Monitoring Manager for Windows provided by RATOC Systems, Inc. registers a Windows service with an unquoted f... |
| CVE-2025-55671 | HIGH | 8.5 | 0.1% | Sep 5, 2025 | Uncontrolled search path element issue exists in TkEasyGUI versions prior to v1.0.22. If this vulnerability is exploited... |
| CVE-2025-9990 | HIGH | 8.1 | 0.7% | Sep 5, 2025 | The WordPress Helpdesk Integration plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and... |
| CVE-2025-58362 | HIGH | 7.5 | 0.5% | Sep 5, 2025 | Hono is a Web application framework that provides support for any JavaScript runtime. Versions 4.8.0 through 4.9.5 conta... |
| CVE-2025-55242 | HIGH | 7.5 | 0.8% | Sep 4, 2025 | Exposure of sensitive information to an unauthorized actor in Xbox allows an unauthorized attacker to disclose informati... |
| CVE-2025-55238 | HIGH | 7.5 | 0.8% | Sep 4, 2025 | Dynamics 365 FastTrack Implementation Assets Information Disclosure Vulnerability |
| CVE-2025-58353 | HIGH | 8.2 | 0.2% | Sep 4, 2025 | Promptcraft Forge Studio is a toolkit for evaluating, optimizing, and maintaining LLM-powered applications. All version... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now