2025 CVE Vulnerabilities
45,207 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11269 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The Product Filter by WBW plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capab... |
| CVE-2025-11244 | LOW | 3.7 | 0.3% | Oct 25, 2025 | The Password Protected plugin for WordPress is vulnerable to authorization bypass via IP address spoofing in all version... |
| CVE-2025-11238 | HIGH | 7.2 | 0.2% | Oct 25, 2025 | The Watu Quiz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP Referer header in versions ... |
| CVE-2025-10737 | MEDIUM | 6.4 | 0.2% | Oct 25, 2025 | The Open Source Genesis Framework theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's short... |
| CVE-2025-10694 | MEDIUM | 5.3 | 0.2% | Oct 25, 2025 | The User Feedback – Create Interactive Feedback Form, User Surveys, and Polls in Seconds plugin for WordPress is vulnera... |
| CVE-2025-11823 | MEDIUM | 5.4 | 0.2% | Oct 25, 2025 | The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +21 Modules – All in One Solution plugin for WordPress is... |
| CVE-2025-10579 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The BackWPup – WordPress Backup & Restore Plugin plugin for WordPress is vulnerable to unauthorized access of data due t... |
| CVE-2025-11760 | MEDIUM | 5.3 | 0.3% | Oct 25, 2025 | The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposu... |
| CVE-2025-34503 | HIGH | 7 | 0.1% | Oct 24, 2025 | Deck Mate 1 executes firmware directly from an external EEPROM without verifying authenticity or integrity. An attacker ... |
| CVE-2025-34502 | HIGH | 7 | 0.2% | Oct 24, 2025 | Deck Mate 2 lacks a verified secure-boot chain and runtime integrity validation for its controller and display modules. ... |
| CVE-2025-34500 | HIGH | 7 | 0.1% | Oct 24, 2025 | Deck Mate 2's firmware update mechanism accepts packages without cryptographic signature verification, encrypts them wit... |
| CVE-2025-12194 | MEDIUM | 5.9 | 0.1% | Oct 24, 2025 | Uncontrolled Resource Consumption vulnerability in Legion of the Bouncy Castle Inc. Bouncy Castle for Java FIPS bc-fips ... |
| CVE-2025-62711 | LOW | 3.1 | 0.4% | Oct 24, 2025 | Wasmtime is a runtime for WebAssembly. In versions from 38.0.0 to before 38.0.3, the implementation of component-model r... |
| CVE-2025-4106 | HIGH | 8.9 | 0.3% | Oct 24, 2025 | An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable ... |
| CVE-2025-34293 | HIGH | 8.6 | 0.4% | Oct 24, 2025 | GN4 Publishing System versions prior to 2.6 contain an insecure direct object reference (IDOR) vulnerability via the API... |
| CVE-2025-62723 | MEDIUM | 4.3 | 0.3% | Oct 24, 2025 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.23.2, any authenticated user ca... |
| CVE-2025-62717 | CRITICAL | 9.1 | 0.4% | Oct 24, 2025 | Emlog is an open source website building system. In version 2.5.23, Emlog Pro is vulnerable to a session verification co... |
| CVE-2025-60954 | HIGH | 8.3 | 0.4% | Oct 24, 2025 | Microweber CMS 2.0 has Weak Password Requirements. The application does not enforce minimum password length or complexit... |
| CVE-2025-52099 | — | — | — | Oct 24, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: CVE-2025-29088. Reason: This record is a duplicate of CVE-2025-... |
| CVE-2025-62716 | HIGH | 8.1 | 0.3% | Oct 24, 2025 | Plane is open-source project management software. Prior to version 1.1.0, an open redirect vulnerability in the ?next_pa... |
| CVE-2025-60419 | MEDIUM | 6.2 | 0.1% | Oct 24, 2025 | An issue was discovered in the NDIS Usermode IO driver (RtkIOAC60.sys, version 6.0.5600.16348) allowing local authentica... |
| CVE-2025-60735 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installPlugin function |
| CVE-2025-60731 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has a File Upload vulnerability in the installTheme function |
| CVE-2025-60730 | HIGH | 7.6 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has an arbitrary file deletion vulnerability in the unInstallTheme function |
| CVE-2025-60729 | MEDIUM | 5.3 | 0.3% | Oct 24, 2025 | PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now