2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-11051 | MEDIUM | 6.5 | 0.2% | Sep 27, 2025 | A vulnerability has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknow... |
| CVE-2025-9816 | HIGH | 7.2 | 9.1% | Sep 27, 2025 | The WP Statistics – The Most Popular Privacy-Friendly Analytics Plugin plugin for WordPress is vulnerable to Stored Cros... |
| CVE-2025-3193 | HIGH | 7.5 | 0.5% | Sep 27, 2025 | Versions of the package algoliasearch-helper from 2.0.0-rc1 and before 3.11.2 are vulnerable to Prototype Pollution in t... |
| CVE-2025-11050 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /periodo-lancamento. E... |
| CVE-2025-10954 | HIGH | 7.5 | 0.4% | Sep 27, 2025 | Versions of the package github.com/nyaruka/phonenumbers before 1.2.2 are vulnerable to Improper Validation of Syntactic ... |
| CVE-2025-11049 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of ... |
| CVE-2025-10499 | MEDIUM | 4.3 | 0.2% | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-10498 | MEDIUM | 5.4 | 0.2% | Sep 27, 2025 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2025-8440 | MEDIUM | 6.4 | 0.2% | Sep 27, 2025 | The Team Members plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the first and last name fields in... |
| CVE-2025-36239 | MEDIUM | 6.1 | 0.2% | Sep 27, 2025 | IBM Storage TS4500 Library 1.11.0.0 and 2.11.0.0 is vulnerable to cross-site scripting. This vulnerability allows an u... |
| CVE-2025-59945 | HIGH | 8.1 | 0.3% | Sep 27, 2025 | SysReptor is a fully customizable pentest reporting platform. In versions from 2024.74 to before 2025.83, authenticated ... |
| CVE-2025-59939 | HIGH | 8.8 | 0.3% | Sep 27, 2025 | WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks... |
| CVE-2025-59938 | MEDIUM | 6.5 | 0.3% | Sep 27, 2025 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions starting from ... |
| CVE-2025-59936 | CRITICAL | 9.4 | 0.4% | Sep 27, 2025 | get-jwks contains fetch utils for JWKS keys. In versions prior to 11.0.2, a vulnerability in get-jwks can lead to cache ... |
| CVE-2025-59932 | HIGH | 8.2 | 0.3% | Sep 27, 2025 | Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previo... |
| CVE-2025-36144 | MEDIUM | 5.5 | 0.1% | Sep 27, 2025 | IBM Lakehouse (watsonx.data 2.2) stores potentially sensitive information in log files that could be read by a local use... |
| CVE-2025-59934 | CRITICAL | 9.4 | 8.0% | Sep 26, 2025 | Formbricks is an open source qualtrics alternative. Prior to version 4.0.1, Formbricks is missing JWT signature verifica... |
| CVE-2025-59845 | HIGH | 8.2 | 0.1% | Sep 26, 2025 | Apollo Studio Embeddable Explorer & Embeddable Sandbox are website embeddable software solutions from Apollo GraphQL. Pr... |
| CVE-2025-11048 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A security vulnerability has been detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unkno... |
| CVE-2025-11047 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file /module/Ap... |
| CVE-2025-11046 | CRITICAL | 9.8 | 0.4% | Sep 26, 2025 | A security flaw has been discovered in Tencent WeKnora 0.1.0. This impacts the function testEmbeddingModel of the file /... |
| CVE-2025-11045 | HIGH | 7.3 | 2.0% | Sep 26, 2025 | A vulnerability was identified in WAYOS LQ_04, LQ_05, LQ_06, LQ_07 and LQ_09 22.03.17. This affects an unknown function ... |
| CVE-2025-10657 | HIGH | 8.7 | 0.1% | Sep 26, 2025 | In a hardened Docker environment, with Enhanced Container Isolation ( ECI https://docs.docker.com/enterprise/security/ha... |
| CVE-2025-57692 | MEDIUM | 6.8 | 0.3% | Sep 26, 2025 | PiranhaCMS 12.0 allows stored XSS in the Text content block of Standard and Standard Archive Pages via /manager/pages, e... |
| CVE-2025-50879 | — | — | — | Sep 26, 2025 | Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further inv... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now