2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60099 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awsm.in Embed Any ... |
| CVE-2025-60098 | MEDIUM | 6.5 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in Jeff Farthing Theme My Login theme-my-login allows Exploiting Incorrectly Configu... |
| CVE-2025-60097 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in CodexThemes TheGem thegem allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-60096 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in CodexThemes TheGem (Elementor) thegem-elementor allows Exploiting Incorrectly Con... |
| CVE-2025-60095 | MEDIUM | 4.3 | 0.3% | Sep 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg... |
| CVE-2025-60094 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in Benjamin Intal Stackable stackable-ultimate-gutenberg-blocks allows Exploiting In... |
| CVE-2025-60093 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjada Download Manager download-manager allows Cross Site Request ... |
| CVE-2025-60092 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Shahjada Download Manager do... |
| CVE-2025-60040 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in fkrauthan wp-mpdf ... |
| CVE-2025-58919 | MEDIUM | 5.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in guihom Wide Banner wide-banner allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-58917 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Nick Verwymeren Qu... |
| CVE-2025-58914 | MEDIUM | 4.3 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Di Themes Di Themes Demo Site Importer di-themes-demo-site-importer a... |
| CVE-2025-48326 | MEDIUM | 6.5 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in Acclectic Media Acclectic Media Organizer acclectic-media-organizer allows Exploi... |
| CVE-2025-27006 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themeplugs Authors... |
| CVE-2025-10867 | MEDIUM | 6.5 | 0.3% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.... |
| CVE-2025-54831 | MEDIUM | 6.5 | 0.9% | Sep 26, 2025 | Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict... |
| CVE-2025-1396 | MEDIUM | 5.3 | 0.2% | Sep 26, 2025 | A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this con... |
| CVE-2025-10490 | MEDIUM | 4.4 | 0.2% | Sep 26, 2025 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2025-10307 | MEDIUM | 6.5 | 0.6% | Sep 26, 2025 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to i... |
| CVE-2025-10180 | MEDIUM | 6.4 | 0.3% | Sep 26, 2025 | The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho... |
| CVE-2025-10137 | MEDIUM | 5.4 | 0.3% | Sep 26, 2025 | The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2... |
| CVE-2025-10136 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' s... |
| CVE-2025-9490 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versi... |
| CVE-2025-9985 | MEDIUM | 5.3 | 11.1% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2025-9984 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now