2025 CVE Vulnerabilities

45,233 CVEs published in 2025.

CVE IDSeverityCVSSDescription
CVE-2025-10766MEDIUM4.3A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file Event...
CVE-2025-10765HIGH7.2A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Sug...
CVE-2025-10764HIGH8.8A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.Eve...
CVE-2025-10763MEDIUM6.3A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by th...
CVE-2025-10762MEDIUM6.3A vulnerability was found in kuaifan DooTask up to 1.2.49. Affected by this vulnerability is an unknown functionality of...
CVE-2025-10761LOW3.7A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the compon...
CVE-2025-10760MEDIUM6.3A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/loo...
CVE-2025-10759MEDIUM5.5A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token...
CVE-2025-10758MEDIUM4.8A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file...
CVE-2025-10757HIGH8.8A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file...
CVE-2025-10756HIGH8.8A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /g...
CVE-2025-10755MEDIUM6.3A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component...
CVE-2025-40925CRITICAL9.1Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash...
CVE-2025-10741MEDIUM6.3A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown funct...
CVE-2025-9887MEDIUM4.3The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t...
CVE-2025-9883MEDIUM6.1The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
CVE-2025-9882MEDIUM6.1The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu...
CVE-2025-10658MEDIUM6.5The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass...
CVE-2025-9949MEDIUM4.3The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i...
CVE-2025-10489MEDIUM4.3The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPres...
CVE-2025-10305MEDIUM5.3The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the d...
CVE-2025-10181MEDIUM6.4The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ...
CVE-2025-10002MEDIUM4.9The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is...
CVE-2025-59727Rejected reason: Not used
CVE-2025-59726Rejected reason: Not used

Check if your code is affected by 2025 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now