2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9849 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The Html Social share buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zm_sh_... |
| CVE-2025-7368 | MEDIUM | 5.3 | 0.3% | Sep 6, 2025 | The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to Information ... |
| CVE-2025-7366 | HIGH | 7.3 | 0.3% | Sep 6, 2025 | The The REHub - Price Comparison, Multi Vendor Marketplace Wordpress Theme theme for WordPress is vulnerable to arbitrar... |
| CVE-2025-6067 | MEDIUM | 6.4 | 0.2% | Sep 6, 2025 | The Easy Social Feed – Social Photos Gallery – Post Feed – Like Box plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2025-58439 | CRITICAL | 9.1 | 0.3% | Sep 6, 2025 | ERP is a free and open source Enterprise Resource Planning tool. In versions below 14.89.2 and 15.0.0 through 15.75.1, l... |
| CVE-2025-58375 | HIGH | 8.1 | 0.3% | Sep 6, 2025 | Frappe is a full-stack web application framework. Versions 14.96.9 and below, and 15.0.0 through 15.71.0 have an insecur... |
| CVE-2025-58373 | MEDIUM | 6.5 | 0.3% | Sep 5, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul... |
| CVE-2025-58372 | CRITICAL | 9.8 | 0.5% | Sep 5, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vul... |
| CVE-2025-58371 | CRITICAL | 9.8 | 0.8% | Sep 5, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. In versions 3.26.6 and below, a Github w... |
| CVE-2025-58370 | HIGH | 8.1 | 0.4% | Sep 5, 2025 | Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions below 3.26.0 contain a vulnerab... |
| CVE-2025-58369 | MEDIUM | 5.3 | 0.4% | Sep 5, 2025 | fs2 is a compositional, streaming I/O library for Scala. Versions up to and including 2.5.12, 3.0.0-M1 through 3.12.2, a... |
| CVE-2025-58367 | CRITICAL | 10 | 1.1% | Sep 5, 2025 | DeepDiff is a project focused on Deep Difference and search of any Python data. Versions 5.0.0 through 8.6.0 are vulnera... |
| CVE-2025-58366 | CRITICAL | 9.4 | 0.3% | Sep 5, 2025 | Onyxia is a data science environment for kubernetes. In versions 4.6.0 through 4.8.0, Onyxia-API leaked the credentials ... |
| CVE-2025-57807 | CRITICAL | 9.8 | 0.3% | Sep 5, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lowe... |
| CVE-2025-10027 | MEDIUM | 6.1 | 0.3% | Sep 5, 2025 | A vulnerability was determined in itsourcecode POS Point of Sale System 1.0. Affected by this issue is some unknown func... |
| CVE-2025-53791 | MEDIUM | 4.7 | 0.4% | Sep 5, 2025 | Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature ... |
| CVE-2025-10061 | MEDIUM | 6.5 | 0.3% | Sep 5, 2025 | An authorized user can cause a crash in the MongoDB Server through a specially crafted $group query. This vulnerability ... |
| CVE-2025-10060 | HIGH | 7.5 | 0.3% | Sep 5, 2025 | MongoDB Server may allow upsert operations retried within a transaction to violate unique index constraints, potentially... |
| CVE-2025-10059 | MEDIUM | 6.5 | 0.3% | Sep 5, 2025 | An improper setting of the lsid field on any sharded query can cause a crash in MongoDB routers. This issue occurs when ... |
| CVE-2025-9566 | HIGH | 8.1 | 1.1% | Sep 5, 2025 | There's a vulnerability in podman where an attacker may use the kube play command to overwrite host files when the kube ... |
| CVE-2025-10044 | MEDIUM | 4.3 | 0.3% | Sep 5, 2025 | A flaw was found in Keycloak. Keycloak’s account console and other pages accept arbitrary text in the error_description ... |
| CVE-2025-10043 | — | — | — | Sep 5, 2025 | Rejected reason: Considered by the maintainers a bug scenario experienced rather than a vulnerability. |
| CVE-2025-10026 | MEDIUM | 6.1 | 0.3% | Sep 5, 2025 | A vulnerability was found in itsourcecode POS Point of Sale System 1.0. Affected by this vulnerability is an unknown fun... |
| CVE-2025-10025 | CRITICAL | 9.8 | 0.4% | Sep 5, 2025 | A vulnerability has been found in PHPGurukul Online Course Registration 3.1. Affected is an unknown function of the file... |
| CVE-2025-9057 | MEDIUM | 6.4 | 0.2% | Sep 5, 2025 | The Biagiotti Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now