2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-10193 | HIGH | 7.4 | 0.2% | Sep 11, 2025 | DNS rebinding vulnerability in Neo4j Cypher MCP server allows malicious websites to bypass Same-Origin Policy protection... |
| CVE-2025-10251 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | A vulnerability was detected in FoxCMS up to 1.24. Affected by this issue is the function batchCope of the file /app/adm... |
| CVE-2025-9018 | HIGH | 8.8 | 0.3% | Sep 11, 2025 | The Time Tracker plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capab... |
| CVE-2025-40696 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ... |
| CVE-2025-40695 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ... |
| CVE-2025-40694 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a stored authenticated ... |
| CVE-2025-40693 | MEDIUM | 5.4 | 0.2% | Sep 11, 2025 | Stored Cross Site Scripting in Online Fire Reporting System v1.2 by PHPGurukul, that consists in a reflected and stored ... |
| CVE-2025-40692 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40691 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40690 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40689 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-40687 | CRITICAL | 9.8 | 0.3% | Sep 11, 2025 | SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, cre... |
| CVE-2025-10250 | MEDIUM | 5 | 0.2% | Sep 11, 2025 | A weakness has been identified in DJI Mavic Spark, Mavic Air and Mavic Mini 01.00.0500. Affected is an unknown function ... |
| CVE-2025-58321 | CRITICAL | 10 | 1.2% | Sep 11, 2025 | Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. |
| CVE-2025-58320 | HIGH | 7.3 | 13.1% | Sep 11, 2025 | Delta Electronics DIALink has an Directory Traversal Authentication Bypass Vulnerability. |
| CVE-2025-48041 | HIGH | 7.1 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-48040 | MEDIUM | 6.9 | 0.4% | Sep 11, 2025 | Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Floodi... |
| CVE-2025-48039 | MEDIUM | 5.3 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-48038 | MEDIUM | 5.3 | 0.4% | Sep 11, 2025 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive... |
| CVE-2025-9918 | HIGH | 8.7 | 0.6% | Sep 11, 2025 | A Path Traversal vulnerability in the archive extraction component in Google SecOps SOAR Server (versions 6.3.54.0, 6.3.... |
| CVE-2025-9874 | HIGH | 7.5 | 0.5% | Sep 11, 2025 | The Ultimate Classified Listings plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and i... |
| CVE-2025-9861 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The ThemeLoom Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'los_showposts'... |
| CVE-2025-9860 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Mixtape plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mixtape' shortcode in al... |
| CVE-2025-9855 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Enhanced BibliPlug plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bibliplug_aut... |
| CVE-2025-9850 | MEDIUM | 6.4 | 0.2% | Sep 11, 2025 | The Evenium plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'evenium_single_event' sh... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now