2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48040 | MEDIUM | 6.9 | 0.4% | Sep 11, 2025 | Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodi... |
| CVE-2025-48039 | MEDIUM | 5.3 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-48038 | MEDIUM | 5.3 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-9861 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts'... |
| CVE-2025-9860 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in al... |
| CVE-2025-9855 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_aut... |
| CVE-2025-9850 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' sh... |
| CVE-2025-9635 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Analytics Reduce Bounce Rate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9634 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-9633 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The LH Signing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-9632 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The PhpList Subber plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-9631 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The AutoCatSet plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.... |
| CVE-2025-9628 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The The integration of the AMO.CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-9627 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Run Log plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.1... |
| CVE-2025-9623 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Admin in English with Switch plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-9620 | MEDIUM | 6.1 | 0.1% | Sep 11, 2025 | The Seo Monster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3... |
| CVE-2025-9617 | MEDIUM | 5.3 | 0.1% | Sep 11, 2025 | The Publish approval plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-9451 | MEDIUM | 6.5 | 0.3% | Sep 11, 2025 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parame... |
| CVE-2025-9128 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The eID Easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up... |
| CVE-2025-9123 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The CBX Map for Google Map & OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the pop... |
| CVE-2025-8721 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Workable Api plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's workable_jobs shortc... |
| CVE-2025-8692 | MEDIUM | 4.9 | 0.4% | Sep 11, 2025 | The Coupon API plugin for WordPress is vulnerable to SQL Injection via the ‘log_duration’ parameter in all versions up t... |
| CVE-2025-8691 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The WP Scriptcase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' parameter in all versi... |
| CVE-2025-8689 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Elements Plus! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Comparison, ... |
| CVE-2025-8686 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The WP Easy FAQs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's WP_EASY_FAQ shortcod... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now