2025 CVE Vulnerabilities
45,230 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10871 | HIGH | 7.2 | 0.4% | Sep 26, 2025 | An issue has been discovered in GitLab EE affecting all versions from 16.6 before 18.2.7, 18.3 before 18.3.3, and 18.4 b... |
| CVE-2025-10867 | MEDIUM | 6.5 | 0.3% | Sep 26, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.... |
| CVE-2025-10858 | HIGH | 7.5 | 0.6% | Sep 26, 2025 | An issue was discovered in GitLab CE/EE affecting all versions before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1... |
| CVE-2025-54831 | MEDIUM | 6.5 | 0.9% | Sep 26, 2025 | Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict... |
| CVE-2025-1396 | MEDIUM | 5.3 | 0.2% | Sep 26, 2025 | A username enumeration vulnerability exists in multiple WSO2 products when Multi-Attribute Login is enabled. In this con... |
| CVE-2025-35027 | HIGH | 7.3 | 2.3% | Sep 26, 2025 | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a com... |
| CVE-2025-10490 | MEDIUM | 4.4 | 0.2% | Sep 26, 2025 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all v... |
| CVE-2025-10307 | MEDIUM | 6.5 | 0.6% | Sep 26, 2025 | The Backuply – Backup, Restore, Migrate and Clone plugin for WordPress is vulnerable to arbitrary file deletion due to i... |
| CVE-2025-10180 | MEDIUM | 6.4 | 0.3% | Sep 26, 2025 | The Markdown Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'markdown' sho... |
| CVE-2025-10137 | MEDIUM | 5.4 | 0.3% | Sep 26, 2025 | The Snow Monkey theme for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2... |
| CVE-2025-10136 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The TweetThis Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tweetthis' s... |
| CVE-2025-9490 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Popup Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versi... |
| CVE-2025-10747 | HIGH | 7.2 | 0.6% | Sep 26, 2025 | The WP-DownloadManager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation ... |
| CVE-2025-9985 | MEDIUM | 5.3 | 11.1% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions ... |
| CVE-2025-9984 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to unauthorized access of data due to a missing ca... |
| CVE-2025-10037 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_posts_with_internal_f... |
| CVE-2025-10036 | MEDIUM | 4.9 | 0.3% | Sep 26, 2025 | The Featured Image from URL (FIFU) plugin for WordPress is vulnerable to SQL Injection via the get_all_urls() function i... |
| CVE-2025-9044 | MEDIUM | 6.4 | 0.2% | Sep 26, 2025 | The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple fields in versions up... |
| CVE-2025-11000 | MEDIUM | 5.5 | 0.2% | Sep 26, 2025 | A vulnerability was determined in Open Babel up to 3.1.1. This affects the function PQSFormat::ReadMolecule of the file ... |
| CVE-2025-10745 | MEDIUM | 5.3 | 0.3% | Sep 26, 2025 | The Banhammer – Monitor Site Traffic, Block Bad Users and Bots plugin for WordPress is vulnerable to Blocking Bypass in ... |
| CVE-2025-10377 | MEDIUM | 4.3 | 0.2% | Sep 26, 2025 | The System Dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includi... |
| CVE-2025-10173 | LOW | 2.7 | 0.2% | Sep 26, 2025 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution plugin for WordPress is vulnerable ... |
| CVE-2025-60033 | — | — | — | Sep 26, 2025 | Rejected reason: Not used |
| CVE-2025-60032 | — | — | — | Sep 26, 2025 | Rejected reason: Not used |
| CVE-2025-60031 | — | — | — | Sep 26, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now