2025 CVE Vulnerabilities
45,319 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15692 | LOW | 3.5 | 0.2% | Sep 2, 2026 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting ... |
| CVE-2025-15490 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users t... |
| CVE-2025-15489 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated u... |
| CVE-2025-15485 | HIGH | 8.2 | 0.2% | Sep 2, 2026 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowin... |
| CVE-2025-15481 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all ... |
| CVE-2025-13398 | — | — | — | Sep 2, 2026 | Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the sam... |
| CVE-2025-7963 | MEDIUM | 6.4 | 0.2% | Sep 2, 2026 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywavefor... |
| CVE-2025-15664 | MEDIUM | 6.8 | 0.3% | Sep 2, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's b... |
| CVE-2025-15663 | MEDIUM | 6.8 | 0.3% | Sep 2, 2026 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's a... |
| CVE-2025-46418 | HIGH | 7.6 | 0.7% | Sep 2, 2026 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. |
| CVE-2025-12768 | HIGH | 8.6 | — | Sep 1, 2026 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could e... |
| CVE-2025-15613 | MEDIUM | 6.5 | 0.3% | Sep 1, 2026 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attack... |
| CVE-2025-63607 | MEDIUM | 6.1 | 0.2% | Aug 31, 2026 | TechStore 1.0 is vulnerable to Cross Site Scripting (XSS). In contact_display, the application echoes the id parameter v... |
| CVE-2025-64649 | MEDIUM | 5.9 | 0.2% | Aug 28, 2026 | IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te... |
| CVE-2025-36290 | MEDIUM | 5.9 | 0.2% | Aug 28, 2026 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid... |
| CVE-2025-36271 | MEDIUM | 5.9 | 0.2% | Aug 28, 2026 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a... |
| CVE-2025-30156 | HIGH | 8.9 | 0.1% | Aug 28, 2026 | Ceph is an open-source distributed storage platform providing object, block, and file storage. In versions prior to 20.2... |
| CVE-2025-62343 | LOW | 3.1 | 0.2% | Aug 27, 2026 | HCL IntelliOps Event Management (IEM) is affected by an Admin Session Concurrency Vulnerability. it may allows user sess... |
| CVE-2025-62342 | MEDIUM | 6.4 | 0.2% | Aug 27, 2026 | HCL IntelliOps Event Management (IEM) is affected by a Session Deletion Vulnerability. It may allow improper handling of... |
| CVE-2025-62341 | LOW | 3.7 | 0.1% | Aug 26, 2026 | HCL Connections is vulnerable to server-side request forgery (SSRF) when an internal server is compromised possibly allo... |
| CVE-2025-61480 | HIGH | 7.5 | 0.1% | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ... |
| CVE-2025-61479 | HIGH | 7.5 | 0.2% | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ... |
| CVE-2025-61478 | HIGH | 7.5 | 0.3% | Aug 26, 2026 | An issue in Vanderbilt Industries, Acre Security SPC5300.000 Main Board v.3.14.1 allows a physically proximate attacker ... |
| CVE-2025-51679 | CRITICAL | 9.1 | 0.4% | Aug 26, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. A mismatch between the RTL and netlist can lead to unexpected ... |
| CVE-2025-51675 | HIGH | 7.5 | 0.3% | Aug 26, 2026 | An issue was discovered in openRISC OR1200 commit 83ac6b. An inaccurate update of program counter (PC) values when SPR c... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now