2025 CVE Vulnerabilities
45,264 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28963 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Req... |
| CVE-2025-28957 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez ... |
| CVE-2025-28951 | CRITICAL | 9.1 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in CreedAlly Bulk Featured Image bulk-featured-image allow... |
| CVE-2025-27358 | MEDIUM | 4.6 | 0.2% | Jul 4, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Man... |
| CVE-2025-27326 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Video Gal... |
| CVE-2025-26591 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam WP fancy... |
| CVE-2025-24764 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in A. Jones (Simply) ... |
| CVE-2025-24757 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in AndonDesign uDesign udesign.This issue affects uDesign: from n/a through <= 4.11.... |
| CVE-2025-24748 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in ThemeFusion Avada avada.This issue affects Avada: from n/a through <= 7.11.10. |
| CVE-2025-24735 | HIGH | 7.7 | 0.4% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Chatra Chatra Live... |
| CVE-2025-23972 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Brian S. Reed Contact Form 7 reCAPTCHA contact-form-7-recaptcha allow... |
| CVE-2025-6673 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The Easy restaurant menu manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's nsc_... |
| CVE-2025-53600 | HIGH | 7.5 | 0.2% | Jul 4, 2025 | Whale browser before 4.32.315.22 allow an attacker to bypass the Same-Origin Policy in a dual-tab environment. |
| CVE-2025-53599 | CRITICAL | 9.8 | 0.4% | Jul 4, 2025 | Whale browser for iOS before 3.9.1.4206 allow an attacker to execute malicious scripts in the browser via a crafted java... |
| CVE-2025-32918 | HIGH | 8.8 | 0.3% | Jul 4, 2025 | Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions... |
| CVE-2025-6944 | MEDIUM | 6.4 | 0.2% | Jul 4, 2025 | The Uncode Core plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'uncode_hl_text' and ... |
| CVE-2025-5372 | HIGH | 8.8 | 0.4% | Jul 4, 2025 | A flaw was found in libssh versions built with OpenSSL versions older than 3.0, specifically in the ssh_kdf() function r... |
| CVE-2025-7053 | MEDIUM | 6.1 | 0.3% | Jul 4, 2025 | A vulnerability was found in Cockpit up to 2.11.3. It has been rated as problematic. This issue affects some unknown pro... |
| CVE-2025-7046 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The Portfolio for Elementor & Image Gallery | PowerFolio plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2025-6814 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | The Booking X plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the... |
| CVE-2025-6787 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | The Smart Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartdocs_search' sho... |
| CVE-2025-6786 | MEDIUM | 5.3 | 0.3% | Jul 4, 2025 | The DocCheck Login plugin for WordPress is vulnerable to unauthorized post access in all versions up to, and including, ... |
| CVE-2025-6783 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the emdedSc() functi... |
| CVE-2025-6782 | HIGH | 7.5 | 0.3% | Jul 4, 2025 | The GoZen Forms plugin for WordPress is vulnerable to SQL Injection via the 'forms-id' parameter of the dirGZActiveForm(... |
| CVE-2025-6739 | MEDIUM | 6.5 | 0.3% | Jul 4, 2025 | The WPQuiz plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'wpquiz' shortcode in all v... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now