2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-12205 | HIGH | 7.8 | 0.2% | Oct 27, 2025 | A vulnerability was detected in Kamailio 5.5. The affected element is the function sr_push_yy_state of the file src/core... |
| CVE-2025-12204 | HIGH | 7.8 | 0.3% | Oct 27, 2025 | A security vulnerability has been detected in Kamailio 5.5. Impacted is the function rve_destroy of the file src/core/rv... |
| CVE-2025-12203 | MEDIUM | 4.9 | 0.4% | Oct 27, 2025 | A weakness has been identified in givanz Vvveb up to 1.0.7.3. This issue affects the function sanitizeFileName of the fi... |
| CVE-2025-62988 | MEDIUM | 4.9 | 0.1% | Oct 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Codeless Slider Templates slider-templates allows Server Side Reques... |
| CVE-2025-62987 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Builderall Builder... |
| CVE-2025-62986 | HIGH | 7.1 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in FanBridge FanBridge signup fanbridge-signup allows Stored XSS.This is... |
| CVE-2025-62985 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in llamaman Simple Pu... |
| CVE-2025-62984 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPeka WP AdCenter ... |
| CVE-2025-62983 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sudar Muthu Posts ... |
| CVE-2025-62982 | MEDIUM | 5.9 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sarah Giles Dynami... |
| CVE-2025-62981 | MEDIUM | 4.7 | 0.2% | Oct 27, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks WP Gravity Forms Zoho CRM and Bigin gf-zo... |
| CVE-2025-62980 | MEDIUM | 5.4 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in MDZ Persian Admnin Fonts persian-admin-fonts allows Exploiting Incorrectly Config... |
| CVE-2025-62979 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in airesvsg ACF to REST API acf-to-rest-api allows Retri... |
| CVE-2025-62978 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Kiotviet KiotViet Sync kiotvietsync allows Exploiting Incorrectly Configured Acce... |
| CVE-2025-62977 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in 沃之涛 百度站长SEO合集(支持百度/神马/Bing/头条推送) baiduseo allows Accessing Functionality Not Prop... |
| CVE-2025-62976 | MEDIUM | 5.3 | 0.3% | Oct 27, 2025 | Missing Authorization vulnerability in Joovii Sendle Shipping official-sendle-shipping-method allows Accessing Functiona... |
| CVE-2025-62975 | MEDIUM | 4.3 | 0.1% | Oct 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in raychat Raychat raychat allows Cross Site Request Forgery.This issue ... |
| CVE-2025-62974 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CoSchedule Headlin... |
| CVE-2025-62973 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Themekraft BuddyForms buddyforms allows Accessing Functionality Not Properly Cons... |
| CVE-2025-62972 | MEDIUM | 4.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in WPWebinarSystem WebinarPress wp-webinarsystem allows Exploiting Incorrectly Confi... |
| CVE-2025-62971 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrestaProject Atte... |
| CVE-2025-62970 | MEDIUM | 5.3 | 0.2% | Oct 27, 2025 | Missing Authorization vulnerability in Spencer Haws Link Whisper Free link-whisper allows Exploiting Incorrectly Configu... |
| CVE-2025-62969 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in XLPlugins NextMove... |
| CVE-2025-62968 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sayan Datta WP Las... |
| CVE-2025-62967 | MEDIUM | 6.5 | 0.2% | Oct 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Designinvento Dire... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now