2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-24771 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OTWthemes Content ... |
| CVE-2025-23970 | CRITICAL | 9.8 | 0.7% | Jul 4, 2025 | Incorrect Privilege Assignment vulnerability in aonetheme Service Finder Booking sf-booking allows Privilege Escalation.... |
| CVE-2025-7060 | HIGH | 8.1 | 0.4% | Jul 4, 2025 | A vulnerability was found in Monitorr up to 1.7.6m. It has been classified as problematic. This affects an unknown part ... |
| CVE-2025-38176 | HIGH | 7.8 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: binder: fix use-after-free in binderfs_evict_inode(... |
| CVE-2025-38175 | HIGH | 7.8 | 0.1% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: binder: fix yet another UAF in binder_devices Comm... |
| CVE-2025-38174 | MEDIUM | 5.5 | 0.2% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration ... |
| CVE-2025-5920 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | The Sharable Password Protected Posts before version 1.1.1 allows access to password protected posts by providing a secr... |
| CVE-2025-5351 | MEDIUM | 6.5 | 0.5% | Jul 4, 2025 | A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for co... |
| CVE-2025-53569 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Lib... |
| CVE-2025-53568 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station allows Cross Site Request Forg... |
| CVE-2025-53566 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-30983 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip... |
| CVE-2025-30979 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Pixelatin... |
| CVE-2025-30969 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus iFrame Im... |
| CVE-2025-30947 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in gopiplus Cool fade... |
| CVE-2025-30943 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Pos... |
| CVE-2025-30929 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-29012 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorre... |
| CVE-2025-29007 | MEDIUM | 4.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in LMSACE LMSACE Connect lmsace-connect allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-29001 | MEDIUM | 4.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-28971 | MEDIUM | 5.9 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer E... |
| CVE-2025-28969 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in cybio Gallery Widg... |
| CVE-2025-28967 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Steve Truman Conta... |
| CVE-2025-28963 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Req... |
| CVE-2025-28957 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now