2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-64868 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64866 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64854 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64838 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64830 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64618 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64610 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64589 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64588 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64584 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-... |
| CVE-2025-64542 | MEDIUM | 5.4 | 0.2% | Sep 8, 2026 | Adobe Experience Manager is affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit ... |
| CVE-2025-52657 | LOW | 3.5 | 0.2% | Sep 7, 2026 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the... |
| CVE-2025-52652 | LOW | 3.5 | 0.1% | Sep 7, 2026 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content,... |
| CVE-2025-52651 | LOW | 3.5 | 0.1% | Sep 7, 2026 | HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause u... |
| CVE-2025-9049 | HIGH | 8.8 | 0.2% | Sep 5, 2026 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a mi... |
| CVE-2025-15647 | MEDIUM | 5.5 | 0.1% | Sep 5, 2026 | CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge in... |
| CVE-2025-15614 | LOW | 3.3 | 0.1% | Sep 5, 2026 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z arc... |
| CVE-2025-15694 | LOW | 3.5 | 0.2% | Sep 5, 2026 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before output... |
| CVE-2025-15693 | LOW | 2.7 | 0.3% | Sep 5, 2026 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its admini... |
| CVE-2025-14945 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scri... |
| CVE-2025-67066 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtyp... |
| CVE-2025-15691 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before cre... |
| CVE-2025-12737 | HIGH | 8.4 | 0.2% | Sep 3, 2026 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This ov... |
| CVE-2025-9314 | CRITICAL | 9.8 | 0.3% | Sep 2, 2026 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in th... |
| CVE-2025-8945 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now