2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9958 | HIGH | 7.7 | 0.5% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18... |
| CVE-2025-9642 | CRITICAL | 9.6 | 0.5% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18... |
| CVE-2025-7691 | HIGH | 8.8 | 0.3% | Sep 26, 2025 | A privilege escalation issue has been discovered in GitLab EE affecting all versions from 16.6 prior to 18.2.7, 18.3 pri... |
| CVE-2025-60219 | CRITICAL | 10 | 0.4% | Sep 26, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme WooCommerce Designer Pro wc-designer-pro allo... |
| CVE-2025-60186 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Alex Moss Google+ ... |
| CVE-2025-60185 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kontur.us kontur A... |
| CVE-2025-60184 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Terry L. SEO Searc... |
| CVE-2025-60181 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Server-Side Request Forgery (SSRF) vulnerability in silence Silencesoft RSS Reader external-rss-reader allows Server Sid... |
| CVE-2025-60179 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Space Studio Click... |
| CVE-2025-60177 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rozx Recaptcha – w... |
| CVE-2025-60173 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ashwani kumar GST for WooCommerce gst-for-woocommerce allows Stored X... |
| CVE-2025-60172 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in flytedesk Flytedesk Digital flytedesk-digital allows Stored XSS.This ... |
| CVE-2025-60171 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in yourplugins Conditional Cart Messages for WooCommerce – YourPlugins.c... |
| CVE-2025-60170 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Store... |
| CVE-2025-60169 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in W3S Cloud Technology W3SCloud Contact Form 7 to Zoho CRM w3s-cf7-zoho... |
| CVE-2025-60167 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in honzat Page Manager for Elem... |
| CVE-2025-60166 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in wpshuffle WP Subscription Forms PRO wp-subscription-forms-pro allows Exploiting I... |
| CVE-2025-60165 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | Missing Authorization vulnerability in HaruTheme Frames frames allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-60164 | HIGH | 7.1 | 0.1% | Sep 26, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in NewsMAN NewsmanApp newsmanapp allows Stored XSS.This issue affects Ne... |
| CVE-2025-60163 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Robin W bbp topic ... |
| CVE-2025-60162 | MEDIUM | 6.5 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PickPlugins Job Bo... |
| CVE-2025-60161 | MEDIUM | 5.4 | 0.2% | Sep 26, 2025 | Server-Side Request Forgery (SSRF) vulnerability in bdthemes ZoloBlocks zoloblocks allows Server Side Request Forgery.Th... |
| CVE-2025-60160 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sharkthemes Smart ... |
| CVE-2025-60159 | MEDIUM | 4.3 | 0.3% | Sep 26, 2025 | Missing Authorization vulnerability in webmaniabr Nota Fiscal Eletrônica WooCommerce nota-fiscal-eletronica-woocommerce ... |
| CVE-2025-60158 | MEDIUM | 5.9 | 0.2% | Sep 26, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in webmaniabr Nota Fi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now