2025 CVE Vulnerabilities
45,158 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10759 | MEDIUM | 5.5 | 0.3% | Sep 21, 2025 | A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token... |
| CVE-2025-10758 | MEDIUM | 4.8 | 0.3% | Sep 21, 2025 | A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file... |
| CVE-2025-10755 | MEDIUM | 6.3 | 0.2% | Sep 20, 2025 | A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component... |
| CVE-2025-10741 | MEDIUM | 6.3 | 0.3% | Sep 20, 2025 | A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown funct... |
| CVE-2025-9887 | MEDIUM | 4.3 | 0.1% | Sep 20, 2025 | The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-9883 | MEDIUM | 6.1 | 0.1% | Sep 20, 2025 | The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-9882 | MEDIUM | 6.1 | 0.1% | Sep 20, 2025 | The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-10658 | MEDIUM | 6.5 | 0.3% | Sep 20, 2025 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2025-9949 | MEDIUM | 4.3 | 0.2% | Sep 20, 2025 | The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-10489 | MEDIUM | 4.3 | 0.2% | Sep 20, 2025 | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPres... |
| CVE-2025-10305 | MEDIUM | 5.3 | 0.2% | Sep 20, 2025 | The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the d... |
| CVE-2025-10181 | MEDIUM | 6.4 | 0.2% | Sep 20, 2025 | The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ... |
| CVE-2025-10002 | MEDIUM | 4.9 | 0.3% | Sep 20, 2025 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is... |
| CVE-2025-10652 | MEDIUM | 6.5 | 0.3% | Sep 20, 2025 | The Robcore Netatmo plugin for WordPress is vulnerable to SQL Injection via the ‘module_id’ attribute of the robcore-net... |
| CVE-2025-43808 | MEDIUM | 5.3 | 0.3% | Sep 19, 2025 | The Commerce component in Liferay Portal 7.3.0 through 7.4.3.112, and Liferay DXP 2023.Q4.0 through 2023.Q4.8, 2023.Q3.1... |
| CVE-2025-9081 | MEDIUM | 6.5 | 0.3% | Sep 19, 2025 | Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate access controls which allows any authe... |
| CVE-2025-59689 | MEDIUM | 6.1 | 1.9% | Sep 19, 2025 | Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a ... |
| CVE-2025-57396 | MEDIUM | 6.5 | 0.2% | Sep 19, 2025 | Tandoor Recipes 2.0.0-alpha-1, fixed in 2.0.0-alpha-2, is vulnerable to privilege escalation. This is due to the rework ... |
| CVE-2025-56762 | MEDIUM | 6.1 | 0.3% | Sep 19, 2025 | Paracrawl KeOPs v2 is vulnerable to Cross Site Scripting (XSS) in error.php. |
| CVE-2025-43809 | MEDIUM | 4.3 | 0.2% | Sep 19, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in the server (license) registration page in Liferay Portal 7.4.0 throug... |
| CVE-2025-43803 | MEDIUM | 4.3 | 0.3% | Sep 19, 2025 | Insecure direct object reference (IDOR) vulnerability in the Contacts Center widget in Liferay Portal 7.4.0 through 7.4.... |
| CVE-2025-26517 | MEDIUM | 5.4 | 0.2% | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a privilege es... |
| CVE-2025-26516 | MEDIUM | 5.3 | 0.4% | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Denial of Se... |
| CVE-2025-26514 | MEDIUM | 6.4 | 0.2% | Sep 19, 2025 | StorageGRID (formerly StorageGRID Webscale) versions prior to 11.8.0.15 and 11.9.0.8 are susceptible to a Reflected Cr... |
| CVE-2025-10722 | MEDIUM | 5.3 | 0.1% | Sep 19, 2025 | A vulnerability was detected in SKTLab Mukbee App 1.01.196 on Android. This affects an unknown function of the file Andr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now