2025 CVE Vulnerabilities
45,233 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10766 | MEDIUM | 4.3 | 0.5% | Sep 21, 2025 | A weakness has been identified in SeriaWei ZKEACMS up to 4.3. This issue affects the function Download of the file Event... |
| CVE-2025-10765 | HIGH | 7.2 | 0.4% | Sep 21, 2025 | A security flaw has been discovered in SeriaWei ZKEACMS up to 4.3. This vulnerability affects the function CheckPage/Sug... |
| CVE-2025-10764 | HIGH | 8.8 | 0.4% | Sep 21, 2025 | A vulnerability was identified in SeriaWei ZKEACMS up to 4.3. This affects the function Edit of the file src/ZKEACMS.Eve... |
| CVE-2025-10763 | MEDIUM | 6.3 | 0.3% | Sep 21, 2025 | A vulnerability was determined in academico-sis academico up to d9a9e2636fbf7e5845ee086bcb03ca62faceb6ab. Affected by th... |
| CVE-2025-10762 | MEDIUM | 6.3 | 0.3% | Sep 21, 2025 | A vulnerability was found in kuaifan DooTask up to 1.2.49. Affected by this vulnerability is an unknown functionality of... |
| CVE-2025-10761 | LOW | 3.7 | 0.5% | Sep 21, 2025 | A vulnerability has been found in Harness 3.3.0. Affected is an unknown function of the file /api/v1/login of the compon... |
| CVE-2025-10760 | MEDIUM | 6.3 | 0.3% | Sep 21, 2025 | A flaw has been found in Harness 3.3.0. This impacts the function LookupRepo of the file app/api/controller/gitspace/loo... |
| CVE-2025-10759 | MEDIUM | 5.5 | 0.3% | Sep 21, 2025 | A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token... |
| CVE-2025-10758 | MEDIUM | 4.8 | 0.3% | Sep 21, 2025 | A security vulnerability has been detected in htmly up to 3.1.0. The impacted element is an unknown function of the file... |
| CVE-2025-10757 | HIGH | 8.8 | 1.0% | Sep 21, 2025 | A weakness has been identified in UTT 1200GW up to 3.0.0-170831. The affected element is an unknown function of the file... |
| CVE-2025-10756 | HIGH | 8.8 | 0.8% | Sep 20, 2025 | A security flaw has been discovered in UTT HiPER 840G up to 3.1.1-190328. Impacted is an unknown function of the file /g... |
| CVE-2025-10755 | MEDIUM | 6.3 | 0.2% | Sep 20, 2025 | A vulnerability was detected in Selleo Mentingo 2025.08.27. The impacted element is an unknown function of the component... |
| CVE-2025-40925 | CRITICAL | 9.1 | 0.3% | Sep 20, 2025 | Starch versions 0.14 and earlier generate session ids insecurely. The default session id generator returns a SHA-1 hash... |
| CVE-2025-10741 | MEDIUM | 6.3 | 0.3% | Sep 20, 2025 | A security vulnerability has been detected in Selleo Mentingo up to 2025.08.27. The affected element is an unknown funct... |
| CVE-2025-9887 | MEDIUM | 4.3 | 0.1% | Sep 20, 2025 | The Custom Login And Signup Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-9883 | MEDIUM | 6.1 | 0.1% | Sep 20, 2025 | The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-9882 | MEDIUM | 6.1 | 0.1% | Sep 20, 2025 | The osTicket WP Bridge plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inclu... |
| CVE-2025-10658 | MEDIUM | 6.5 | 0.3% | Sep 20, 2025 | The SupportCandy – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2025-9949 | MEDIUM | 4.3 | 0.2% | Sep 20, 2025 | The Internal Links Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-10489 | MEDIUM | 4.3 | 0.2% | Sep 20, 2025 | The SureForms – Drag and Drop Contact Form Builder – Multi-step Forms, Conversational Forms and more plugin for WordPres... |
| CVE-2025-10305 | MEDIUM | 5.3 | 0.2% | Sep 20, 2025 | The Secure Passkeys plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the d... |
| CVE-2025-10181 | MEDIUM | 6.4 | 0.2% | Sep 20, 2025 | The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'drafts' shortcode in ... |
| CVE-2025-10002 | MEDIUM | 4.9 | 0.3% | Sep 20, 2025 | The ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages plugin for WordPress is... |
| CVE-2025-59727 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
| CVE-2025-59726 | — | — | — | Sep 20, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now