2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15647 | MEDIUM | 5.5 | 0.1% | Sep 5, 2026 | CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge in... |
| CVE-2025-14945 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-15691 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before cre... |
| CVE-2025-8945 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be ... |
| CVE-2025-15490 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users t... |
| CVE-2025-15489 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated u... |
| CVE-2025-15481 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all ... |
| CVE-2025-7963 | MEDIUM | 6.4 | 0.2% | Sep 2, 2026 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywavefor... |
| CVE-2025-15664 | MEDIUM | 6.8 | 0.3% | Sep 2, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's b... |
| CVE-2025-15663 | MEDIUM | 6.8 | 0.3% | Sep 2, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's a... |
| CVE-2025-15613 | MEDIUM | 6.5 | 0.3% | Sep 1, 2026 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attack... |
| CVE-2025-63607 | MEDIUM | 6.1 | 0.2% | Aug 31, 2026 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter v... |
| CVE-2025-64649 | MEDIUM | 5.9 | 0.2% | Aug 28, 2026 | IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te... |
| CVE-2025-36290 | MEDIUM | 5.9 | 0.2% | Aug 28, 2026 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid... |
| CVE-2025-36271 | MEDIUM | 5.9 | 0.2% | Aug 28, 2026 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2025-62342 | MEDIUM | 6.4 | 0.2% | Aug 27, 2026 | HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of... |
| CVE-2025-70340 | MEDIUM | 6.5 | 0.2% | Aug 26, 2026 | A Broken Access Control vulnerability exists in ThingsBoard Professional Edition (PE) 4.21 and below, within the Alarms ... |
| CVE-2025-10903 | MEDIUM | 6.5 | 0.4% | Aug 26, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.... |
| CVE-2025-9878 | MEDIUM | 6.4 | — | Aug 25, 2026 | The PPWP – Password Protect WordPress | #1 Most-Reviewed Password Plugin plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2025-36939 | MEDIUM | 5.7 | — | Aug 24, 2026 | Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net... |
| CVE-2025-68833 | MEDIUM | 5.3 | — | Aug 24, 2026 | HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u... |
| CVE-2025-15671 | MEDIUM | 5.4 | — | Aug 21, 2026 | The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and s... |
| CVE-2025-62306 | MEDIUM | 5 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability a... |
| CVE-2025-62300 | MEDIUM | 5.9 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can... |
| CVE-2025-62299 | MEDIUM | 6.6 | — | Aug 20, 2026 | HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to acces... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now