2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54831 | MEDIUM | 6.5 | 0.9% | Sep 26, 2025 | Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict... |
| CVE-2025-1396 | MEDIUM | 5.3 | 0.2% | Sep 26, 2025 | A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this con... |
| CVE-2025-10490 | MEDIUM | 4.4 | 0.2% | Sep 26, 2025 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2025-10307 | MEDIUM | 6.5 | 0.6% | Sep 26, 2025 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to i... |
| CVE-2025-10180 | MEDIUM | 6.4 | 0.3% | Sep 26, 2025 | The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho... |
| CVE-2025-10137 | MEDIUM | 5.4 | 0.3% | Sep 26, 2025 | The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2... |
| CVE-2025-10136 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' s... |
| CVE-2025-9490 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versi... |
| CVE-2025-9985 | MEDIUM | 5.3 | 11.1% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2025-9984 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2025-10037 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_f... |
| CVE-2025-10036 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function i... |
| CVE-2025-9044 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up... |
| CVE-2025-11000 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file ... |
| CVE-2025-10745 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in ... |
| CVE-2025-10377 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-10999 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was found in Open Babel up to 3.1.1. The impacted element is the function CacaoFormat::SetHilderbrandt o... |
| CVE-2025-10998 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability has been found in Open Babel up to 3.1.1. The affected element is the function ChemKinFormat::ReadReacti... |
| CVE-2025-8906 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Widgets for Tiktok Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trustind... |
| CVE-2025-8200 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Mega Elements – Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-10992 | MEDIUM | 5.5 | 0.3% | Sep 26, 2025 | A vulnerability was determined in roncoo roncoo-pay up to 9428382af21cd5568319eae7429b7e1d0332ff40. Affected is an unkno... |
| CVE-2025-10752 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve... |
| CVE-2025-10178 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The CM Business Directory plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cmbd_featu... |
| CVE-2025-60251 | MEDIUM | 5 | 0.2% | Sep 26, 2025 | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 accept any handshake secret with the unitree substring. |
| CVE-2025-60250 | MEDIUM | 4.7 | 0.2% | Sep 26, 2025 | Unitree Go2, G1, H1, and B2 devices through 2025-09-20 decrypt BLE packet data by using the df98b715d5c6ed2b25817b6f2554... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now