2025 CVE Vulnerabilities
45,227 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7721 | CRITICAL | 9.8 | 0.6% | Oct 3, 2025 | The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Local File Incl... |
| CVE-2025-49641 | MEDIUM | 4.3 | 0.3% | Oct 3, 2025 | A regular Zabbix user with no permission to the Monitoring -> Problems view is still able to call the problem.view.refre... |
| CVE-2025-40636 | CRITICAL | 9.3 | 0.3% | Oct 3, 2025 | SQL injection vulnerability in Joomla module mod_vvisit_counter v2.0.4j3. This vulnerability allows an attacker to retri... |
| CVE-2025-27237 | HIGH | 7.3 | 0.3% | Oct 3, 2025 | In Zabbix Agent and Agent 2 on Windows, the OpenSSL configuration file is loaded from a path writable by low-privileged ... |
| CVE-2025-27236 | MEDIUM | 6.5 | 0.3% | Oct 3, 2025 | A regular Zabbix user can search other users in their user group via Zabbix API by select fields the user does not have ... |
| CVE-2025-27231 | MEDIUM | 4.9 | 0.4% | Oct 3, 2025 | The LDAP 'Bind password' value cannot be read after saving, but a Super Admin account can leak it by changing LDAP 'Host... |
| CVE-2025-10726 | CRITICAL | 9.1 | 0.4% | Oct 3, 2025 | The WPRecovery plugin for WordPress is vulnerable to SQL Injection via the 'data[id]' parameter in all versions up to, a... |
| CVE-2025-10582 | HIGH | 8.8 | 0.3% | Oct 3, 2025 | The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and ... |
| CVE-2025-10547 | CRITICAL | 9.8 | 0.6% | Oct 3, 2025 | An uninitialized variable in the HTTP CGI request arguments processing component of Vigor Routers running DrayOS may all... |
| CVE-2025-10311 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The Comment Info Detector plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in... |
| CVE-2025-10309 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The PayPal Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, ... |
| CVE-2025-10306 | LOW | 3.8 | 0.3% | Oct 3, 2025 | The Backup Bolt plugin for WordPress is vulnerable to arbitrary file downloads and backup location writes in all version... |
| CVE-2025-10302 | MEDIUM | 4.3 | 0.1% | Oct 3, 2025 | The Ultimate Viral Quiz plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and incl... |
| CVE-2025-10212 | MEDIUM | 5.3 | 0.3% | Oct 3, 2025 | The SiteAlert (Formerly WP Health) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2025-10192 | MEDIUM | 6.4 | 0.3% | Oct 3, 2025 | The WP Photo Effects plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wppe_effect' sh... |
| CVE-2025-10165 | MEDIUM | 6.4 | 0.2% | Oct 3, 2025 | The AP Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adv_parallax_back'... |
| CVE-2025-10053 | MEDIUM | 4.4 | 0.2% | Oct 3, 2025 | The TableGen – Data Table Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings... |
| CVE-2025-0876 | MEDIUM | 4.1 | 0.2% | Oct 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Isin Basi A... |
| CVE-2025-11234 | HIGH | 7.5 | 0.8% | Oct 3, 2025 | A flaw was found in QEMU. If the QIOChannelWebsock object is freed while it is waiting to complete a handshake, a GSourc... |
| CVE-2025-6388 | CRITICAL | 9.8 | 0.5% | Oct 3, 2025 | The Spirit Framework plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1... |
| CVE-2025-11223 | HIGH | 8.4 | 0.1% | Oct 3, 2025 | Installer of Panasonic AutoDownloader version 1.2.8 contains an issue with the DLL search path, which may lead ... |
| CVE-2025-0616 | HIGH | 8.2 | 0.3% | Oct 3, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Teknolojik Center ... |
| CVE-2025-61671 | — | — | — | Oct 3, 2025 | Rejected reason: Further research determined the issue is not an open source vulnerability. |
| CVE-2025-61599 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | Emlog is an open source website building system. A stored Cross-Site Scripting (XSS) vulnerability exists in the "Twitte... |
| CVE-2025-61597 | MEDIUM | 5.4 | 0.2% | Oct 3, 2025 | Emlog is an open source website building system. In versions 2.5.21 and below, an HTML template injection allows stored ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now