2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8492 | MEDIUM | 5.3 | 0.3% | Sep 11, 2025 | The Salon Booking System, Appointment Scheduling for Salons, Spas & Small Businesses plugin for WordPress is vulnerable ... |
| CVE-2025-8481 | MEDIUM | 4.3 | 0.1% | Sep 11, 2025 | The Blog Designer For Elementor – Post Slider, Post Carousel, Post Grid plugin for WordPress is vulnerable to Cross-Site... |
| CVE-2025-8445 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Countdown Timer for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'countdown_l... |
| CVE-2025-8423 | MEDIUM | 5.4 | 0.3% | Sep 11, 2025 | The My WP Translate plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability ... |
| CVE-2025-8398 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The azurecurve BBCode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'url' shortcode... |
| CVE-2025-8392 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Mitfahrgelegenheit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in all... |
| CVE-2025-8318 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Jobify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘keyword’ parameter in all versions... |
| CVE-2025-8316 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Certifica WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘evento’ parameter in all ver... |
| CVE-2025-8215 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Responsive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple widge... |
| CVE-2025-5801 | MEDIUM | 6.4 | 0.3% | Sep 11, 2025 | The Digital Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘column’ parameter... |
| CVE-2025-0763 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2025-8479 | MEDIUM | 4.3 | 0.2% | Sep 11, 2025 | The Zoho Flow plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.14.1.... |
| CVE-2025-9034 | MEDIUM | 6.1 | 0.2% | Sep 11, 2025 | The Wp Edit Password Protected WordPress plugin before 1.3.5 does not validate a parameter before redirecting the user ... |
| CVE-2025-10247 | MEDIUM | 6.3 | 0.3% | Sep 11, 2025 | A security vulnerability has been detected in JEPaaS 7.2.8. This vulnerability affects the function doFilterInternal of ... |
| CVE-2025-9910 | MEDIUM | 4.7 | 0.3% | Sep 11, 2025 | Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeB... |
| CVE-2025-9776 | MEDIUM | 6.5 | 0.4% | Sep 11, 2025 | The CatFolders – Tame Your WordPress Media Library by Category plugin for WordPress is vulnerable to time-based SQL Inje... |
| CVE-2025-10245 | MEDIUM | 4.3 | 0.3% | Sep 11, 2025 | A security flaw has been discovered in Display Painéis TGA up to 7.1.41. Affected by this issue is some unknown function... |
| CVE-2025-10235 | MEDIUM | 4.8 | 0.3% | Sep 11, 2025 | A flaw has been found in Scada-LTS up to 2.7.8.1. This issue affects some unknown processing of the file /reports.shtm o... |
| CVE-2025-10234 | MEDIUM | 4.8 | 0.3% | Sep 11, 2025 | A vulnerability was detected in Scada-LTS up to 2.7.8.1. This vulnerability affects unknown code of the file /data_point... |
| CVE-2025-10233 | MEDIUM | 4.3 | 0.4% | Sep 10, 2025 | A security vulnerability has been detected in kalcaddle kodbox 1.61. This affects the function fileGet/fileSave of the f... |
| CVE-2025-10232 | MEDIUM | 5.4 | 0.5% | Sep 10, 2025 | A weakness has been identified in 299ko up to 2.0.0. Affected by this issue is the function getSentDir/delete of the fil... |
| CVE-2025-10229 | MEDIUM | 4.3 | 0.3% | Sep 10, 2025 | A vulnerability has been found in Freshwork up to 1.2.3. This impacts an unknown function of the file /api/v2/logout. Su... |
| CVE-2025-43783 | MEDIUM | 6.1 | 0.2% | Sep 10, 2025 | Reflected cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.3.73 through 7.4.3.128, and Liferay DXP 2024.Q3... |
| CVE-2025-10211 | MEDIUM | 6.3 | 0.7% | Sep 10, 2025 | A security vulnerability has been detected in yanyutao0402 ChanCMS 3.3.0. The affected element is the function CollectCo... |
| CVE-2025-9714 | MEDIUM | 5.5 | 0.1% | Sep 10, 2025 | Uncontrolled recursion in XPath evaluation in libxml2 up to and including version 2.9.14 allows a local attacker to caus... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now