2025 CVE Vulnerabilities
45,142 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49408 | CRITICAL | 10 | 0.5% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in WPDeveloper Templately allows Retrieve Embedded Sensi... |
| CVE-2025-49400 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-49381 | CRITICAL | 9.6 | 0.2% | Aug 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Si... |
| CVE-2025-48169 | CRITICAL | 9.9 | 0.4% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Rem... |
| CVE-2025-48148 | CRITICAL | 10 | 14.9% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe... |
| CVE-2025-9187 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Memory safety bugs present in Firefox 141 and Thunderbird 141. Some of these bugs showed evidence of memory corruption a... |
| CVE-2025-9179 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | An attacker was able to perform memory corruption in the GMP process which processes encrypted media. This process is al... |
| CVE-2025-8042 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerab... |
| CVE-2025-55031 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Malicious pages could use Firefox for iOS to pass FIDO: links to the OS and trigger the hybrid passkey transport. An att... |
| CVE-2025-54145 | CRITICAL | 9.1 | 0.4% | Aug 19, 2025 | The QR scanner could allow arbitrary websites to be opened if a user was tricked into scanning a malicious link that lev... |
| CVE-2025-54143 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictio... |
| CVE-2025-9156 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | A vulnerability was found in itsourcecode Sports Management System 1.0. The affected element is an unknown function of t... |
| CVE-2025-9155 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | A vulnerability has been found in itsourcecode Online Tour and Travel Management System 1.0. Impacted is an unknown func... |
| CVE-2025-51543 | CRITICAL | 9.8 | 0.3% | Aug 19, 2025 | An issue was discovered in Cicool builder 3.4.4 allowing attackers to reset the administrator's password via the /admini... |
| CVE-2025-9154 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | A flaw has been found in itsourcecode Online Tour and Travel Management System 1.0. This issue affects some unknown proc... |
| CVE-2025-55733 | CRITICAL | 9.6 | 0.6% | Aug 19, 2025 | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click r... |
| CVE-2025-55306 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | GenX_FX is an advance IA trading platform that will focus on forex trading. A vulnerability was identified in the GenX F... |
| CVE-2025-9149 | CRITICAL | 9.8 | 5.6% | Aug 19, 2025 | A vulnerability was determined in Wavlink WL-NU516U1 M16U1_V240425. This impacts the function sub_4032E4 of the file /cg... |
| CVE-2025-55294 | CRITICAL | 9.8 | 1.5% | Aug 19, 2025 | screenshot-desktop allows capturing a screenshot of your local machine. This vulnerability is a command injection issue.... |
| CVE-2025-54336 | CRITICAL | 9.8 | 0.5% | Aug 19, 2025 | In Plesk Obsidian 18.0.70, _isAdminPasswordValid uses an == comparison. Thus, if the correct password is "0e" followed b... |
| CVE-2025-50567 | CRITICAL | 10 | 0.7% | Aug 19, 2025 | Saurus CMS Community Edition 4.7.1 contains a vulnerability in the custom DB::prepare() function, which uses preg_replac... |
| CVE-2025-8723 | CRITICAL | 9.8 | 14.0% | Aug 19, 2025 | The Cloudflare Image Resizing plugin for WordPress is vulnerable to Remote Code Execution due to missing authentication ... |
| CVE-2025-6758 | CRITICAL | 9.8 | 0.4% | Aug 19, 2025 | The Real Spaces - WordPress Properties Directory Theme theme for WordPress is vulnerable to privilege escalation via the... |
| CVE-2025-55591 | CRITICAL | 9.8 | 7.2% | Aug 18, 2025 | TOTOLINK-A3002R v4.0.0-B20230531.1404 was discovered to contain a command injection vulnerability in the devicemac param... |
| CVE-2025-55213 | CRITICAL | 9.8 | 0.3% | Aug 18, 2025 | OpenFGA is a high-performance and flexible authorization/permission engine built for developers and inspired by Google Z... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now