2025 CVE Vulnerabilities
45,225 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-39929 | MEDIUM | 5.5 | 0.1% | Oct 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: smb: client: fix smbdirect_recv_io leak in smbd_neg... |
| CVE-2025-9952 | MEDIUM | 6.1 | 0.3% | Oct 4, 2025 | The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to R... |
| CVE-2025-9886 | MEDIUM | 4.3 | 0.2% | Oct 4, 2025 | The Trinity Audio – Text to Speech AI audio player to convert content into audio plugin for WordPress is vulnerable to C... |
| CVE-2025-10383 | MEDIUM | 6.4 | 0.2% | Oct 4, 2025 | The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to Stored Cross-Site... |
| CVE-2025-9485 | CRITICAL | 9.8 | 0.6% | Oct 4, 2025 | The OAuth Single Sign On – SSO (OAuth Client) plugin for WordPress is vulnerable to Improper Verification of Cryptograph... |
| CVE-2025-9243 | HIGH | 8.1 | 0.3% | Oct 4, 2025 | The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorizedmodification of data due to a missing capa... |
| CVE-2025-9030 | MEDIUM | 5.4 | 0.2% | Oct 4, 2025 | The Majestic Before After Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'before_label'... |
| CVE-2025-9029 | MEDIUM | 4.3 | 0.2% | Oct 4, 2025 | The WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder plugin for WordPres... |
| CVE-2025-8726 | MEDIUM | 5.4 | 0.2% | Oct 4, 2025 | The WP Photo Album Plus plugin for WordPress is vulnerable to Cross-Site Scripting in all versions up to, and including,... |
| CVE-2025-61962 | MEDIUM | 5.9 | 0.4% | Oct 4, 2025 | In fetchmail before 6.5.6, the SMTP client can crash when authenticating upon receiving a 334 status code in a malformed... |
| CVE-2025-61895 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61894 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61893 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61892 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61891 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61890 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61889 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61888 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-61887 | — | — | — | Oct 4, 2025 | Rejected reason: Not used |
| CVE-2025-11228 | MEDIUM | 5.3 | 0.3% | Oct 4, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized modification of... |
| CVE-2025-11227 | MEDIUM | 6.5 | 0.3% | Oct 4, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Information Exposure in all ... |
| CVE-2025-10746 | MEDIUM | 6.5 | 0.2% | Oct 4, 2025 | The Integrate Dynamics 365 CRM plugin for WordPress is vulnerable to unauthorized access in all versions up to, and incl... |
| CVE-2025-10751 | HIGH | 7.8 | 0.2% | Oct 4, 2025 | MacForge contains an insecure XPC service that allows local, unprivileged users to escalate their privileges to root.Thi... |
| CVE-2025-61685 | MEDIUM | 6.5 | 0.5% | Oct 3, 2025 | Mastra is a Typescript framework for building AI agents and assistants. Versions 0.13.8 through 0.13.20-alpha.0 are vuln... |
| CVE-2025-61681 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | KUNO CMS is a fully deployable full-stack blog application. Versions 1.3.13 and below contain validation flaws in its fi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now