2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9232 | MEDIUM | 5.9 | 2.0% | Sep 30, 2025 | Issue summary: An application using the OpenSSL HTTP client API functions may trigger an out-of-bounds read if the 'no_p... |
| CVE-2025-9231 | MEDIUM | 6.5 | 2.2% | Sep 30, 2025 | Issue summary: A timing side-channel which could potentially allow remote recovery of the private key exists in the SM2 ... |
| CVE-2025-52050 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | In Frappe ERPNext 15.57.5, the function get_loyalty_program_details_with_points() at erpnext/accounts/doctype/loyalty_pr... |
| CVE-2025-52049 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | In Frappe ErpNext v15.57.5, the function get_timesheet_detail_rate() at erpnext/projects/doctype/timesheet/timesheet.py ... |
| CVE-2025-52047 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | In Frappe ErpNext v15.57.5, the function get_income_account() at erpnext/controllers/queries.py is vulnerable to SQL Inj... |
| CVE-2025-52043 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | In Frappe ERPNext v15.57.5, the function import_coa() at erpnext/accounts/doctype/chart_of_accounts_importer/chart_of_ac... |
| CVE-2025-10859 | MEDIUM | 4 | 0.1% | Sep 30, 2025 | Cookie storage for non-HTML temporary documents was being shared incorrectly with normal browsing content, allowing info... |
| CVE-2025-10217 | MEDIUM | 6 | 0.3% | Sep 30, 2025 | A vulnerability exists in Asset Suite for an authenticated user to manipulate the content of performance related log dat... |
| CVE-2025-9948 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | The Chat by Chatwee plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includin... |
| CVE-2025-9946 | MEDIUM | 6.1 | 0.1% | Sep 30, 2025 | The LockerPress – WordPress Security Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all vers... |
| CVE-2025-9852 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Yoga Schedule Momoyoga plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'momoyoga-... |
| CVE-2025-8777 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The planetcalc plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘language’ parameter in all ver... |
| CVE-2025-8624 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Nexa Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Google Maps widget in... |
| CVE-2025-8623 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The WeedMaps Menu for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's weedm... |
| CVE-2025-8608 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Mihdan: Elementor Yandex Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's blo... |
| CVE-2025-8566 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The GutenBee – Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via parameters in the ... |
| CVE-2025-8560 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The FancyTabs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all version... |
| CVE-2025-8559 | MEDIUM | 6.5 | 0.4% | Sep 30, 2025 | The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1... |
| CVE-2025-8214 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The The Pack Elementor addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typing L... |
| CVE-2025-8119 | MEDIUM | 4.3 | 0.1% | Sep 30, 2025 | PAD CMS is vulnerable to Cross-Site Request Forgery in reset password's functionality. Malicious attacker can craft spec... |
| CVE-2025-8118 | MEDIUM | 6.5 | 0.2% | Sep 30, 2025 | PAD CMS implements weak client-side brute-force protection by utilizing two cookies: login_count and login_timeout. Inf... |
| CVE-2025-8116 | MEDIUM | 6.1 | 0.2% | Sep 30, 2025 | PAD CMS is vulnerable to Reflected XSS in printing and save to PDF functionality. Malicious attacker can craft special U... |
| CVE-2025-6941 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-6815 | MEDIUM | 5.5 | 0.2% | Sep 30, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-59956 | MEDIUM | 6.5 | 0.4% | Sep 30, 2025 | AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now