2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-34068 | CRITICAL | 9.3 | 0.9% | Jul 15, 2025 | An unauthenticated remote command execution vulnerability exists in Samsung WLAN AP WEA453e firmware prior to version 5.... |
| CVE-2025-7667 | HIGH | 8.1 | 0.3% | Jul 15, 2025 | The Restrict File Access plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and inc... |
| CVE-2025-4369 | MEDIUM | 5.5 | 0.2% | Jul 15, 2025 | The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ ... |
| CVE-2025-24477 | MEDIUM | 6.7 | 0.2% | Jul 15, 2025 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS... |
| CVE-2025-7672 | MEDIUM | 4.3 | 0.2% | Jul 15, 2025 | The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS... |
| CVE-2025-3621 | CRITICAL | 9.6 | 0.8% | Jul 15, 2025 | Vulnerabilities* in ActADUR local server product, developed and maintained by ProTNS, allows Remote Code Inclusion on ho... |
| CVE-2025-7367 | MEDIUM | 6.4 | 0.2% | Jul 15, 2025 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie... |
| CVE-2025-7360 | CRITICAL | 9.8 | 1.3% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-7341 | CRITICAL | 9.8 | 1.1% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-7340 | CRITICAL | 9.8 | 1.6% | Jul 15, 2025 | The HT Contact Form Widget For Elementor Page Builder & Gutenberg Blocks & Form Builder plugin for WordPress is vulnerab... |
| CVE-2025-5394 | CRITICAL | 9.8 | 47.8% | Jul 15, 2025 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file uploads ... |
| CVE-2025-5393 | CRITICAL | 9.1 | 0.5% | Jul 15, 2025 | The Alone – Charity Multipurpose Non-profit WordPress Theme theme for WordPress is vulnerable to arbitrary file deletion... |
| CVE-2025-6265 | HIGH | 7.2 | 0.5% | Jul 15, 2025 | A path traversal vulnerability in the file_upload-cgi CGI program of Zyxel NWA50AX PRO firmware version 7.10(ACGE.2) and... |
| CVE-2025-53891 | MEDIUM | 4.3 | 0.3% | Jul 15, 2025 | The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found... |
| CVE-2025-53890 | CRITICAL | 9.8 | 1.1% | Jul 15, 2025 | pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoa... |
| CVE-2025-53889 | MEDIUM | 6.5 | 0.4% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to... |
| CVE-2025-53887 | MEDIUM | 5.3 | 0.5% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53886 | MEDIUM | 4.5 | 0.4% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53885 | MEDIUM | 4.2 | 0.2% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53839 | MEDIUM | 4 | 0.2% | Jul 15, 2025 | DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interfac... |
| CVE-2025-53836 | HIGH | 8.8 | 0.5% | Jul 15, 2025 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-53835 | CRITICAL | 9 | 0.3% | Jul 14, 2025 | XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) int... |
| CVE-2025-53834 | MEDIUM | 6.3 | 0.2% | Jul 14, 2025 | Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s... |
| CVE-2025-53833 | CRITICAL | 10 | 9.4% | Jul 14, 2025 | LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior ... |
| CVE-2025-53825 | CRITICAL | 9.8 | 0.5% | Jul 14, 2025 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to version 0.24.3, an unauthenticated preview deplo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now