2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7052 | HIGH | 8.8 | 0.2% | Sep 30, 2025 | The LatePoint plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.1... |
| CVE-2025-7038 | HIGH | 8.2 | 0.4% | Sep 30, 2025 | The LatePoint plugin for WordPress is vulnerable to Authentication Bypass due to insufficient identity verification with... |
| CVE-2025-6941 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-6815 | MEDIUM | 5.5 | 0.2% | Sep 30, 2025 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-61633 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61632 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61631 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61630 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61629 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61628 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61627 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61626 | — | — | — | Sep 30, 2025 | Rejected reason: Not used |
| CVE-2025-61584 | CRITICAL | 9.3 | 0.3% | Sep 30, 2025 | serverless-dns is a RethinkDNS resolver that deploys to Cloudflare Workers, Deno Deploy, Fastly, and Fly.io. Versions th... |
| CVE-2025-59956 | MEDIUM | 6.5 | 0.4% | Sep 30, 2025 | AgentAPI is an HTTP API for Claude Code, Goose, Aider, Gemini, Amp, and Codex. Versions 0.3.3 and below are susceptible ... |
| CVE-2025-59954 | CRITICAL | 9.8 | 0.5% | Sep 30, 2025 | Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote ... |
| CVE-2025-59668 | HIGH | 8.7 | 0.4% | Sep 30, 2025 | Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafte... |
| CVE-2025-41099 | MEDIUM | 6.5 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41098 | HIGH | 7.5 | 0.3% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41097 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41096 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41095 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41094 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41093 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41092 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
| CVE-2025-41091 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | Insecure Direct Object Reference (IDOR) vulnerability in BOLD Workplanner in versions prior to 2.5.25 (4935b438f9b), con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now