2025 CVE Vulnerabilities
45,153 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10037 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_f... |
| CVE-2025-10036 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function i... |
| CVE-2025-9044 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up... |
| CVE-2025-11000 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file ... |
| CVE-2025-10745 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in ... |
| CVE-2025-10377 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-10999 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt o... |
| CVE-2025-10998 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReacti... |
| CVE-2025-8906 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Widgets for Tiktok Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trustind... |
| CVE-2025-8200 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-10992 | MEDIUM | 5.5 | 0.3% | Sep 26, 2025 | A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unkno... |
| CVE-2025-10752 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve... |
| CVE-2025-10178 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featu... |
| CVE-2025-60251 | MEDIUM | 5 | 0.2% | Sep 26, 2025 | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring. |
| CVE-2025-60250 | MEDIUM | 4.7 | 0.2% | Sep 26, 2025 | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554... |
| CVE-2025-10981 | MEDIUM | 6.5 | 0.4% | Sep 26, 2025 | A vulnerability was detected in JeecgBoot up to 3.8.2. This impacts an unknown function of the file /sys/tenant/exportXl... |
| CVE-2025-10980 | MEDIUM | 6.5 | 0.4% | Sep 26, 2025 | A security vulnerability has been detected in JeecgBoot up to 3.8.2. This affects an unknown function of the file /sys/p... |
| CVE-2025-56769 | MEDIUM | 6.5 | 0.3% | Sep 25, 2025 | An issue was discovered in chinabugotech hutool before 5.8.4 allowing attackers to execute arbitrary expressions that le... |
| CVE-2025-10979 | MEDIUM | 6.5 | 0.4% | Sep 25, 2025 | A weakness has been identified in JeecgBoot up to 3.8.2. The impacted element is an unknown function of the file /sys/ro... |
| CVE-2025-10978 | MEDIUM | 6.5 | 0.4% | Sep 25, 2025 | A security flaw has been discovered in JeecgBoot up to 3.8.2. The affected element is an unknown function of the file /s... |
| CVE-2025-10977 | MEDIUM | 5.3 | 0.4% | Sep 25, 2025 | A vulnerability was identified in JeecgBoot up to 3.8.2. Impacted is an unknown function of the file /sys/tenant/deleteB... |
| CVE-2025-10976 | MEDIUM | 5.3 | 0.3% | Sep 25, 2025 | A vulnerability was determined in JeecgBoot up to 3.8.2. This issue affects some unknown processing of the file /api/get... |
| CVE-2025-10975 | MEDIUM | 6.3 | 0.3% | Sep 25, 2025 | A vulnerability was found in GuanxingLu vlarl up to 31abc0baf53ef8f5db666a1c882e1ea64def2997. This vulnerability affects... |
| CVE-2025-10974 | MEDIUM | 6.3 | 0.3% | Sep 25, 2025 | A vulnerability has been found in giantspatula SewKinect up to 7fd963ceb3385af3706af02b8a128a13399dffb1. This affects th... |
| CVE-2025-59402 | MEDIUM | 5.4 | 0.2% | Sep 25, 2025 | Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehos... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now