2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11163 | MEDIUM | 4.3 | 0.2% | Sep 30, 2025 | The SmartCrawl SEO checker, analyzer & optimizer plugin for WordPress is vulnerable to unauthorized modification of data... |
| CVE-2025-11149 | HIGH | 7.5 | 0.5% | Sep 30, 2025 | This affects all versions of the package node-static; all versions of the package @nubosoftware/node-static. The package... |
| CVE-2025-11148 | CRITICAL | 9.8 | 1.4% | Sep 30, 2025 | All versions of the package check-branches are vulnerable to Command Injection check-branches is a command-line tool tha... |
| CVE-2025-10991 | HIGH | 7 | 0.2% | Sep 30, 2025 | The attacker may obtain root access by connecting to the UART port and this vulnerability requires the attacker to have ... |
| CVE-2025-10196 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Survey Anyplace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'surveyanyplace_e... |
| CVE-2025-10191 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Big Post Shipping for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's... |
| CVE-2025-10189 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The BP Direct Menus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bpdm_login' shor... |
| CVE-2025-10182 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The dbview plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dbview' shortcode in all ... |
| CVE-2025-10179 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The My AskAI plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'myaskai' shortcode in a... |
| CVE-2025-10168 | MEDIUM | 6.4 | 0.3% | Sep 30, 2025 | The Any News Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'any-ticker' shor... |
| CVE-2025-10131 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The All Social Share Options plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sc' sho... |
| CVE-2025-10130 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Layers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'webcam' shortcode in all ... |
| CVE-2025-10128 | MEDIUM | 6.4 | 0.2% | Sep 30, 2025 | The Eulerpool Research Systems plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'aaq' ... |
| CVE-2025-10000 | MEDIUM | 6.4 | 0.4% | Sep 30, 2025 | The Qyrr – simply and modern QR-Code creation plugin for WordPress is vulnerable to arbitrary file uploads due to missin... |
| CVE-2025-61586 | MEDIUM | 5.3 | 0.4% | Sep 30, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below are vulnerable to directory enumeration by s... |
| CVE-2025-59952 | HIGH | 8.7 | 0.5% | Sep 30, 2025 | MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 comp... |
| CVE-2025-59950 | MEDIUM | 5.4 | 0.3% | Sep 30, 2025 | FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.3 and below, due to a bypass of double clickjacking p... |
| CVE-2025-59948 | MEDIUM | 5.4 | 0.3% | Sep 29, 2025 | FreshRSS is a free, self-hostable RSS aggregator. Versions 1.26.3 and below do not sanitize certain event handler attrib... |
| CVE-2025-59942 | HIGH | 7.5 | 0.3% | Sep 29, 2025 | go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.6 and below, go-f3 panics when it v... |
| CVE-2025-59941 | MEDIUM | 6.5 | 0.2% | Sep 29, 2025 | go-f3 is a Golang implementation of Fast Finality for Filecoin (F3). In versions 0.8.8 and below, go-f3's justification ... |
| CVE-2025-59940 | MEDIUM | 6.5 | 0.3% | Sep 29, 2025 | mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerabil... |
| CVE-2025-59937 | CRITICAL | 9.1 | 0.5% | Sep 29, 2025 | go-mail is a comprehensive library for sending mails with Go. In versions 0.7.0 and below, due to incorrect handling of ... |
| CVE-2025-43817 | MEDIUM | 6.1 | 0.2% | Sep 29, 2025 | Multiple reflected cross-site scripting (XSS) vulnerabilities in Liferay Portal 7.4.3.74 through 7.4.3.111, and Liferay ... |
| CVE-2025-43813 | HIGH | 8.2 | 0.5% | Sep 29, 2025 | Possible path traversal vulnerability and denial-of-service in the ComboServlet in Liferay Portal 7.4.0 through 7.4.3.10... |
| CVE-2025-43812 | MEDIUM | 5.4 | 0.2% | Sep 29, 2025 | Cross-site scripting (XSS) vulnerability in web content template in Liferay Portal 7.4.3.4 through 7.4.3.111, and Lifera... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now