2025 CVE Vulnerabilities
45,208 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-62868 | HIGH | 8.1 | 0.4% | Oct 24, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-9978 | MEDIUM | 6.8 | 0.3% | Oct 24, 2025 | The Jeg Kit for Elementor WordPress plugin before 2.7.0 does not sanitize SVG file contents when uploaded via xmlrpc.ph... |
| CVE-2025-9158 | MEDIUM | 5.3 | 0.4% | Oct 24, 2025 | The Request Tracker software is vulnerable to a Stored XSS vulnerability in calendar invitation parsing feature, which d... |
| CVE-2025-61931 | MEDIUM | 5.4 | 0.2% | Oct 24, 2025 | Pleasanter contains a stored cross-site scripting vulnerability in Body, Description and Comments, which allows an attac... |
| CVE-2025-58070 | MEDIUM | 6.1 | 0.2% | Oct 24, 2025 | Pleasanter contains a stored cross-site scripting vulnerability in Preview for Attachments, which allows an attacker to ... |
| CVE-2025-10874 | MEDIUM | 5.5 | 0.2% | Oct 24, 2025 | The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.2... |
| CVE-2025-10723 | LOW | 2.7 | 0.3% | Oct 24, 2025 | The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate pa... |
| CVE-2025-62835 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62834 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62833 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62832 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62831 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62830 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62829 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62828 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-62827 | — | — | — | Oct 24, 2025 | Rejected reason: Not used |
| CVE-2025-7730 | MEDIUM | 6.4 | 0.2% | Oct 23, 2025 | The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘percentage’ parameter i... |
| CVE-2025-62254 | HIGH | 7.5 | 0.5% | Oct 23, 2025 | The ComboServlet in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 th... |
| CVE-2025-60023 | MEDIUM | 6.3 | 0.5% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-59776 | MEDIUM | 6.3 | 0.5% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-58429 | HIGH | 8.3 | 0.6% | Oct 23, 2025 | A relative path traversal vulnerability was discovered in Productivity Suite software version 4.4.1.19. The vulnerabilit... |
| CVE-2025-62688 | HIGH | 7.1 | 0.1% | Oct 23, 2025 | An incorrect permission assignment for a critical resource vulnerability was discovered in Productivity Suite software v... |
| CVE-2025-62498 | HIGH | 8.8 | 0.5% | Oct 23, 2025 | A relative path traversal (ZipSlip) vulnerability was discovered in Productivity Suite software version 4.4.1.19. The ... |
| CVE-2025-61977 | HIGH | 7.3 | 0.1% | Oct 23, 2025 | A weak password recovery mechanism for forgotten password vulnerability was discovered in Productivity Suite software ve... |
| CVE-2025-61934 | CRITICAL | 10 | 0.6% | Oct 23, 2025 | A binding to an unrestricted IP address vulnerability was discovered in Productivity Suite software version v4.4.1.19. T... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now