2025 CVE Vulnerabilities
45,206 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-5949 | HIGH | 8.8 | 0.3% | Nov 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versi... |
| CVE-2025-12118 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Schema Scalpel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title in all versions ... |
| CVE-2025-11995 | HIGH | 7.2 | 0.2% | Nov 1, 2025 | The Community Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event details parameter in al... |
| CVE-2025-11927 | MEDIUM | 4.4 | 0.2% | Nov 1, 2025 | The Flying Images: Optimize and Lazy Load Images for Faster Page Speed plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2025-11377 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The List category posts plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including,... |
| CVE-2025-12367 | MEDIUM | 4.3 | 0.2% | Nov 1, 2025 | The SiteSEO – SEO Simplified plugin for WordPress is vulnerable to Missing Authorization in versions up to, and includin... |
| CVE-2025-11928 | MEDIUM | 4.4 | 0.2% | Nov 1, 2025 | The CSS & JavaScript Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all... |
| CVE-2025-11833 | CRITICAL | 9.8 | 51.0% | Nov 1, 2025 | The Post SMTP – Complete SMTP Solution with Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to... |
| CVE-2025-62275 | MEDIUM | 5.3 | 0.2% | Nov 1, 2025 | Blogs in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.... |
| CVE-2025-11922 | MEDIUM | 6.4 | 0.2% | Nov 1, 2025 | The Inactive Logout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ina_redirect_page_individ... |
| CVE-2025-11920 | HIGH | 8.8 | 0.5% | Nov 1, 2025 | The WPCOM Member plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.7.14... |
| CVE-2025-11816 | MEDIUM | 5.3 | 0.2% | Nov 1, 2025 | The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vul... |
| CVE-2025-11174 | MEDIUM | 5.3 | 0.3% | Nov 1, 2025 | The Document Library Lite plugin for WordPress is vulnerable to Improper Authorization in all versions up to, and includ... |
| CVE-2025-62276 | MEDIUM | 5.5 | 0.1% | Nov 1, 2025 | The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported ver... |
| CVE-2025-12464 | MEDIUM | 6.2 | 0.2% | Oct 31, 2025 | A stack-based buffer overflow was found in the QEMU e1000 network device. The code for padding short frames was dropped ... |
| CVE-2025-63563 | MEDIUM | 6.5 | 0.2% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 does not properly invalidate active user sessions... |
| CVE-2025-63562 | MEDIUM | 6.3 | 0.2% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to v1.0.2 suffers from insufficient server-side authorizati... |
| CVE-2025-63561 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Summer Pearl Group Vacation Rental Management Platform prior to 1.0.2 is susceptible to a Slowloris-style Denial-of-Serv... |
| CVE-2025-60711 | MEDIUM | 6.3 | 0.4% | Oct 31, 2025 | Protection mechanism failure in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a n... |
| CVE-2025-10693 | HIGH | 7.6 | 0.3% | Oct 31, 2025 | When SmartStart Inclusion fails during the onboarding of a Z-Wave PIR sensor, the sensor will join the network as a non-... |
| CVE-2025-64349 | HIGH | 8.8 | 0.3% | Oct 31, 2025 | ELOG allows an authenticated user to modify another user's profile. An attacker can edit a target user's email address, ... |
| CVE-2025-64348 | HIGH | 7.1 | 0.3% | Oct 31, 2025 | ELOG allows an authenticated user to modify or overwrite the configuration file, resulting in denial of service. If the ... |
| CVE-2025-63458 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Tenda AX-1803 v1.0.0.1 was discovered to contain a stack overflow via the timeZone parameter in the form_fast_setting_wi... |
| CVE-2025-63454 | HIGH | 7.5 | 0.4% | Oct 31, 2025 | Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow via the deviceId parameter in the get_parentContro... |
| CVE-2025-62618 | HIGH | 8.6 | 0.3% | Oct 31, 2025 | ELOG allows an authenticated user to upload arbitrary HTML files. The HTML content is executed in the context of other u... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now