2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9979 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The Maspik plugin for WordPress is vulnerable to Missing Authorization in version 2.5.6 and prior. This is due to missin... |
| CVE-2025-9888 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The Maspik – Ultimate Spam Protection plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions u... |
| CVE-2025-9857 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The Heateor Login – Social Login Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin... |
| CVE-2025-9622 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The WP Blast | SEO & Performance Booster plugin for WordPress is vulnerable to Cross-Site Request Forgery in all version... |
| CVE-2025-9463 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v... |
| CVE-2025-9367 | MEDIUM | 5.5 | 0.2% | Sep 10, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up... |
| CVE-2025-8778 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-7843 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u... |
| CVE-2025-7826 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions ... |
| CVE-2025-6189 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter ... |
| CVE-2025-10142 | MEDIUM | 4.9 | 0.4% | Sep 10, 2025 | The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa... |
| CVE-2025-10126 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short... |
| CVE-2025-8388 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-10197 | MEDIUM | 6.3 | 0.2% | Sep 10, 2025 | A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability... |
| CVE-2025-10195 | MEDIUM | 5.3 | 0.1% | Sep 10, 2025 | A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManif... |
| CVE-2025-59044 | MEDIUM | 4.4 | 0.1% | Sep 9, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs f... |
| CVE-2025-9997 | MEDIUM | 5.8 | 0.5% | Sep 9, 2025 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ... |
| CVE-2025-59036 | MEDIUM | 5.5 | 0.2% | Sep 9, 2025 | Infrahub offers a central hub to manage data, templates, and playbooks. Prior to versiond 1.3.9 and 1.4.5, a bug in the ... |
| CVE-2025-58135 | MEDIUM | 6.5 | 0.2% | Sep 9, 2025 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a... |
| CVE-2025-58134 | MEDIUM | 4.3 | 0.2% | Sep 9, 2025 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impa... |
| CVE-2025-58131 | MEDIUM | 6.6 | 0.1% | Sep 9, 2025 | Race condition in the Zoom Workplace VDI Plugin macOS Universal installer for VMware Horizon before version 6.4.10 (or b... |
| CVE-2025-49458 | MEDIUM | 6.5 | 0.3% | Sep 9, 2025 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via net... |
| CVE-2025-9996 | MEDIUM | 5.8 | 0.5% | Sep 9, 2025 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists ... |
| CVE-2025-7746 | MEDIUM | 5.3 | 0.4% | Sep 9, 2025 | CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that c... |
| CVE-2025-54241 | MEDIUM | 5.5 | 0.2% | Sep 9, 2025 | After Effects versions 25.3, 24.6.7 and earlier are affected by an out-of-bounds read vulnerability that could lead to m... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now