2025 CVE Vulnerabilities
45,244 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9463 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Payments Plugin and Checkout Plugin for WooCommerce: Stripe, PayPal, Square, Authorize.net plugin for WordPress is v... |
| CVE-2025-9367 | MEDIUM | 5.5 | 0.2% | Sep 10, 2025 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up... |
| CVE-2025-8778 | MEDIUM | 4.3 | 0.2% | Sep 10, 2025 | The NitroPack plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check ... |
| CVE-2025-7843 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The Auto Save Remote Images (Drafts) plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions u... |
| CVE-2025-7826 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Testimonial plugin for WordPress is vulnerable to SQL Injection via the 'iNICtestimonial' shortcode in all versions ... |
| CVE-2025-7049 | HIGH | 8.8 | 0.3% | Sep 10, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to privilege escalation in all versions u... |
| CVE-2025-6189 | MEDIUM | 6.5 | 0.3% | Sep 10, 2025 | The Duplicate Page and Post plugin for WordPress is vulnerable to time-based SQL Injection via the ‘meta_key’ parameter ... |
| CVE-2025-41714 | HIGH | 8.8 | 0.6% | Sep 10, 2025 | The upload endpoint insufficiently validates the 'Upload-Key' request header. By supplying path traversal sequences, an ... |
| CVE-2025-10142 | MEDIUM | 4.9 | 0.4% | Sep 10, 2025 | The PagBank / PagSeguro Connect para WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'status' pa... |
| CVE-2025-10126 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The MyBrain Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugins's 'mbumap' short... |
| CVE-2025-10049 | HIGH | 7.2 | 0.5% | Sep 10, 2025 | The Responsive Filterable Portfolio plugin for WordPress is vulnerable to arbitrary file uploads due to missing file typ... |
| CVE-2025-10040 | HIGH | 7.7 | 0.3% | Sep 10, 2025 | The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to unauthorized access of dat... |
| CVE-2025-10001 | HIGH | 7.2 | 0.5% | Sep 10, 2025 | The Import any XML, CSV or Excel File to WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to m... |
| CVE-2025-8388 | MEDIUM | 6.4 | 0.2% | Sep 10, 2025 | The PowerPack Elementor Addons (Free Widgets, Extensions and Templates) plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2025-10197 | MEDIUM | 6.3 | 0.2% | Sep 10, 2025 | A vulnerability was found in HJSoft HCM Human Resources Management System up to 20250822. Affected by this vulnerability... |
| CVE-2025-10195 | MEDIUM | 5.3 | 0.1% | Sep 10, 2025 | A vulnerability has been found in Seismic App 2.4.2 on Android. Affected is an unknown function of the file AndroidManif... |
| CVE-2025-59046 | CRITICAL | 9.8 | 1.2% | Sep 9, 2025 | The npm package `interactive-git-checkout` is an interactive command-line tool that allows users to checkout a git branc... |
| CVE-2025-59044 | MEDIUM | 4.4 | 0.1% | Sep 9, 2025 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. Himmelblau 0.9.x derives numeric GIDs f... |
| CVE-2025-59042 | HIGH | 7 | 0.1% | Sep 9, 2025 | PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being ap... |
| CVE-2025-59039 | CRITICAL | 9.3 | 0.3% | Sep 9, 2025 | Prebid Universal Creative (PUC) is a JavaScript API to render multiple formats. Npm users of PUC 1.17.3 or PUC latest we... |
| CVE-2025-59038 | HIGH | 8.6 | 0.3% | Sep 9, 2025 | Prebid.js is a free and open source library for publishers to quickly implement header bidding. NPM users of prebid 10.9... |
| CVE-2025-58750 | CRITICAL | 9.1 | 0.3% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58448 | CRITICAL | 9.8 | 0.3% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-58447 | CRITICAL | 9.8 | 0.8% | Sep 9, 2025 | rAthena is an open-source cross-platform massively multiplayer online role playing game (MMORPG) server. Versions prior ... |
| CVE-2025-10172 | HIGH | 8.8 | 1.0% | Sep 9, 2025 | A flaw has been found in UTT 750W up to 3.2.2-191225. This issue affects some unknown processing of the file /goform/for... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now