2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6054 | MEDIUM | 6.1 | 0.1% | Jul 23, 2025 | The YANewsflash plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2025-5818 | MEDIUM | 5.5 | 0.3% | Jul 23, 2025 | The Featured Image Plus – Quick & Bulk Edit with Unsplash plugin for WordPress is vulnerable to Server-Side Request Forg... |
| CVE-2025-5753 | MEDIUM | 6.4 | 0.2% | Jul 23, 2025 | The Valuation Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter in a... |
| CVE-2025-8060 | HIGH | 8.8 | 0.8% | Jul 23, 2025 | A vulnerability has been found in Tenda AC23 16.03.07.52 and classified as critical. Affected by this vulnerability is t... |
| CVE-2025-54120 | CRITICAL | 9.3 | 0.1% | Jul 23, 2025 | PCL (Plain Craft Launcher) Community Edition is a Minecraft launcher. In PCL CE versions 2.12.0-beta.5 to 2.12.0-beta.9,... |
| CVE-2025-54139 | MEDIUM | 6.1 | 0.3% | Jul 23, 2025 | HAX CMS allows users to manage their microsite universe with a NodeJS or PHP backend. In haxcms-nodejs versions 11.0.12 ... |
| CVE-2025-43489 | MEDIUM | 5.2 | 0.3% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu... |
| CVE-2025-43488 | MEDIUM | 4.8 | 0.2% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu... |
| CVE-2025-43487 | MEDIUM | 6.8 | 0.2% | Jul 23, 2025 | A potential privilege escalation through Sudo vulnerability has been identified in the Poly Clariti Manager for versions... |
| CVE-2025-43486 | MEDIUM | 4.8 | 0.2% | Jul 23, 2025 | A potential stored cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions prior... |
| CVE-2025-43485 | MEDIUM | 4.5 | 0.2% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.2. The vu... |
| CVE-2025-43484 | MEDIUM | 6.1 | 0.2% | Jul 23, 2025 | A potential reflected cross-site scripting vulnerability has been identified in the Poly Clariti Manager for versions pr... |
| CVE-2025-43483 | MEDIUM | 5.7 | 0.1% | Jul 23, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu... |
| CVE-2025-43022 | HIGH | 7.2 | 0.3% | Jul 22, 2025 | A potential SQL injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. T... |
| CVE-2025-43021 | MEDIUM | 5.7 | 0.1% | Jul 22, 2025 | A potential security vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.1. The vu... |
| CVE-2025-43020 | MEDIUM | 6.8 | 0.2% | Jul 22, 2025 | A potential command injection vulnerability has been identified in the Poly Clariti Manager for versions prior to 10.12.... |
| CVE-2025-8011 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-8010 | HIGH | 8.8 | 0.3% | Jul 22, 2025 | Type Confusion in V8 in Google Chrome prior to 138.0.7204.168 allowed a remote attacker to potentially exploit heap corr... |
| CVE-2025-7766 | HIGH | 8.6 | 1.7% | Jul 22, 2025 | Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network d... |
| CVE-2025-54141 | HIGH | 7.5 | 0.8% | Jul 22, 2025 | ViewVC is a browser interface for CVS and Subversion version control repositories. In versions 1.1.0 through 1.1.31 and ... |
| CVE-2025-54140 | HIGH | 7.5 | 0.6% | Jul 22, 2025 | pyLoad is a free and open-source Download Manager written in pure Python. In version 0.5.0b3.dev89, an authenticated pat... |
| CVE-2025-54138 | HIGH | 7.5 | 0.8% | Jul 22, 2025 | LibreNMS is an auto-discovering PHP/MySQL/SNMP based network monitoring which includes support for a wide range of netwo... |
| CVE-2025-54137 | HIGH | 7.3 | 0.3% | Jul 22, 2025 | HAX CMS NodeJS allows users to manage their microsite universe with a NodeJS backend. Versions 11.0.9 and below were dis... |
| CVE-2025-54072 | HIGH | 8.1 | 0.6% | Jul 22, 2025 | yt-dlp is a feature-rich command-line audio/video downloader. In versions 2025.06.25 and below, when the --exec option i... |
| CVE-2025-53703 | HIGH | 8.7 | 0.1% | Jul 22, 2025 | DuraComm SPM-500 DP-10iN-100-MU transmits sensitive data without encryption over a channel that could be intercepted b... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now