2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10499 | MEDIUM | 4.3 | 0.2% | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-10498 | MEDIUM | 5.4 | 0.2% | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-8440 | MEDIUM | 6.4 | 0.2% | Sep 27, 2025 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in... |
| CVE-2025-36239 | MEDIUM | 6.1 | 0.2% | Sep 27, 2025 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u... |
| CVE-2025-59938 | MEDIUM | 6.5 | 0.3% | Sep 27, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from ... |
| CVE-2025-36144 | MEDIUM | 5.5 | 0.1% | Sep 27, 2025 | IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use... |
| CVE-2025-57692 | MEDIUM | 6.8 | 0.3% | Sep 26, 2025 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e... |
| CVE-2025-11034 | MEDIUM | 4.3 | 0.4% | Sep 26, 2025 | A vulnerability was found in Dibo Data Decision Making System up to 2.7.0. The affected element is the function download... |
| CVE-2025-26258 | MEDIUM | 6.1 | 0.2% | Sep 26, 2025 | Sourcecodester Employee Management System v1.0 is vulnerable to Cross Site Scripting (XSS) via 'Add Designation.' |
| CVE-2025-11031 | MEDIUM | 5.5 | 0.8% | Sep 26, 2025 | A flaw has been found in DataTables up to 1.10.13. The affected element is an unknown function of the file /examples/res... |
| CVE-2025-59843 | MEDIUM | 5.3 | 0.4% | Sep 26, 2025 | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[use... |
| CVE-2025-59842 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Archit... |
| CVE-2025-59362 | MEDIUM | 4 | 0.4% | Sep 26, 2025 | Squid through 7.1 mishandles ASN.1 encoding of long SNMP OIDs. This occurs in asn_build_objid in lib/snmplib/asn1.c. |
| CVE-2025-56463 | MEDIUM | 6.8 | 0.2% | Sep 26, 2025 | Mercusys MW305R 3.30 and below is has a Transport Layer Security (TLS) certificate private key disclosure. |
| CVE-2025-11027 | MEDIUM | 5.4 | 0.3% | Sep 26, 2025 | A vulnerability was identified in givanz Vvveb up to 1.0.7.2. Affected by this issue is some unknown functionality of th... |
| CVE-2025-6396 | MEDIUM | 6.1 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Webbeyaz We... |
| CVE-2025-57292 | MEDIUM | 6.1 | 0.2% | Sep 26, 2025 | Todoist v8484 contains a stored cross-site scripting (XSS) vulnerability in the avatar upload functionality. The applica... |
| CVE-2025-11019 | MEDIUM | 4.8 | 0.2% | Sep 26, 2025 | A vulnerability has been found in Total.js CMS up to 19.9.0. This impacts an unknown function of the component Files Men... |
| CVE-2025-11017 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was detected in OGRECave Ogre up to 14.4.1. The impacted element is the function Ogre::LogManager::strea... |
| CVE-2025-11016 | MEDIUM | 4.3 | 0.4% | Sep 26, 2025 | A security vulnerability has been detected in kalcaddle kodbox up to 1.61.09. The affected element is the function fileO... |
| CVE-2025-11015 | MEDIUM | 5.3 | 0.1% | Sep 26, 2025 | A weakness has been identified in OGRECave Ogre up to 14.4.1. Impacted is the function STBIImageCodec::encode of the fil... |
| CVE-2025-11060 | MEDIUM | 5.7 | 0.3% | Sep 26, 2025 | A flaw was found in the live query subscription mechanism of the database engine. This vulnerability allows record or gu... |
| CVE-2025-11025 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Vimesoft Information Technologies and Software Inc. V... |
| CVE-2025-11013 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was identified in BehaviorTree up to 4.7.0. This vulnerability affects the function XMLParser::PImpl::lo... |
| CVE-2025-11011 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was found in BehaviorTree up to 4.7.0. Affected by this issue is the function JsonExporter::fromJson of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now