2025 CVE Vulnerabilities
45,321 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-27129 | CRITICAL | 9.8 | 2.0% | Aug 20, 2025 | An authentication bypass vulnerability exists in the HTTP authentication functionality of Tenda AC6 V5.0 V02.03.01.110. ... |
| CVE-2025-24322 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.... |
| CVE-2025-54726 | CRITICAL | 9.3 | 1.4% | Aug 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS A... |
| CVE-2025-54713 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom... |
| CVE-2025-54049 | CRITICAL | 9.9 | 0.4% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati... |
| CVE-2025-54048 | CRITICAL | 9.3 | 0.4% | Aug 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniOrange Custom ... |
| CVE-2025-54014 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in QuanticaLabs MediCenter - Health Medical Clinic medicenter allows Obj... |
| CVE-2025-53580 | CRITICAL | 9.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in quantumcloud Simple Business Directory Pro simple-business-directory-pro... |
| CVE-2025-53577 | CRITICAL | 10 | 0.4% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Cod... |
| CVE-2025-53299 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in ThemeMakers ThemeMakers Visual Content Composer tmm_content_composer ... |
| CVE-2025-53213 | CRITICAL | 9.9 | 0.3% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ReachShip WooCommerce Multi-Carrier & Cond... |
| CVE-2025-49890 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in ThemeREX Organic Beauty organic-beauty allows Object Injection.This i... |
| CVE-2025-49434 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in axiomthemes Cars4Rent cars4rent allows Object Injection.This issue af... |
| CVE-2025-49422 | CRITICAL | 9.8 | 0.4% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in themepassion Support Ticket support-ticket allows Privilege Escalation.T... |
| CVE-2025-49410 | CRITICAL | 10 | 0.5% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Imran Emu TC Testi... |
| CVE-2025-49409 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in brewlabs SensorPre... |
| CVE-2025-49408 | CRITICAL | 10 | 0.5% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensi... |
| CVE-2025-49400 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-49381 | CRITICAL | 9.6 | 0.2% | Aug 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Si... |
| CVE-2025-48169 | CRITICAL | 9.9 | 0.4% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Rem... |
| CVE-2025-48148 | CRITICAL | 10 | 14.9% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe... |
| CVE-2025-9187 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-9179 | CRITICAL | 9.8 | 0.6% | Aug 19, 2025 | An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is al... |
| CVE-2025-8042 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab... |
| CVE-2025-55031 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now