2025 CVE Vulnerabilities
45,209 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-60852 | MEDIUM | 6.5 | 0.4% | Oct 23, 2025 | A CSV Injection vulnerability existed in Instant Developer Foundation versions prior to 25.0.9600. Applications built wi... |
| CVE-2025-53702 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same l... |
| CVE-2025-53701 | MEDIUM | 6.1 | 0.2% | Oct 23, 2025 | Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET re... |
| CVE-2025-1680 | NONE | 0 | 0.2% | Oct 23, 2025 | An acceptance of extraneous untrusted data with trusted data vulnerability has been identified in Moxa’s Ethernet switch... |
| CVE-2025-1679 | MEDIUM | 4.8 | 0.3% | Oct 23, 2025 | Cross-site Scripting has been identified in Moxa’s Ethernet switches, which allows an authenticated administrative attac... |
| CVE-2025-11429 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | A flaw was found in Keycloak. Keycloak does not immediately enforce the disabling of the "Remember Me" realm setting on ... |
| CVE-2025-8427 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘a... |
| CVE-2025-11128 | MEDIUM | 5 | 0.3% | Oct 23, 2025 | The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator plugin for WordPress is... |
| CVE-2025-11023 | CRITICAL | 9.8 | 0.5% | Oct 23, 2025 | Inclusion of Functionality from Untrusted Control Sphere, Improper Control of Filename for Include/Require Statement in ... |
| CVE-2025-10705 | MEDIUM | 5.3 | 0.3% | Oct 23, 2025 | The MxChat – AI Chatbot for WordPress plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all ver... |
| CVE-2025-62401 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | An issue in Moodle’s timed assignment feature allowed students to bypass the time restriction, potentially giving them m... |
| CVE-2025-62400 | MEDIUM | 6.5 | 0.2% | Oct 23, 2025 | Moodle exposed the names of hidden groups to users who had permission to create calendar events but not to view hidden g... |
| CVE-2025-62399 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | Moodle’s mobile and web service authentication endpoints did not sufficiently restrict repeated password attempts, makin... |
| CVE-2025-62398 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | A serious authentication flaw allowed attackers with valid credentials to bypass multi-factor authentication under certa... |
| CVE-2025-62397 | MEDIUM | 5.3 | 0.3% | Oct 23, 2025 | The router’s inconsistent response to invalid course IDs allowed attackers to infer which course IDs exist, potentially ... |
| CVE-2025-62396 | MEDIUM | 5.3 | 0.3% | Oct 23, 2025 | An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings ... |
| CVE-2025-62395 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | A flaw in the cohort search web service allowed users with permissions in lower contexts to access cohort information fr... |
| CVE-2025-62394 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | Moodle failed to verify enrolment status correctly when sending quiz notifications. As a result, suspended or inactive u... |
| CVE-2025-62393 | MEDIUM | 4.3 | 0.2% | Oct 23, 2025 | A flaw was found in the course overview output function where user access permissions were not fully enforced. This coul... |
| CVE-2025-10355 | MEDIUM | 5.1 | 0.3% | Oct 23, 2025 | Open redirection vulnerability in MOLGENIS EMX2 v11.14.0. This vulnerability allows an attacker to create a malicious UR... |
| CVE-2025-41073 | MEDIUM | 6.5 | 0.3% | Oct 23, 2025 | Path Traversal vulnerability in version 4.4.2236.1 of TESI Gandia Integra Total. This issue allows an authenticated atta... |
| CVE-2025-40643 | MEDIUM | 5.4 | 0.2% | Oct 23, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Energy CRM v2025 by Status Tracker Ltd, consisting of a stored XSS du... |
| CVE-2025-9981 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | QuickCMS is vulnerable to multiple Stored XSS in slider editor functionality (sliders-form). Malicious attacker with adm... |
| CVE-2025-9980 | MEDIUM | 4.8 | 0.2% | Oct 23, 2025 | QuickCMS is vulnerable to multiple Stored XSS in page editor functionality (pages-form). Malicious attacker with admin p... |
| CVE-2025-12105 | HIGH | 7.5 | 0.4% | Oct 23, 2025 | A flaw was found in the asynchronous message queue handling of the libsoup library, widely used by GNOME and WebKit-base... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now