2025 CVE Vulnerabilities
45,331 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48307 | HIGH | 7.1 | 0.1% | Aug 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in kasonzhao SEO For Images seo-for-images allows Stored XSS.This issue ... |
| CVE-2025-48306 | HIGH | 7.1 | 0.1% | Aug 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner savyour-affiliate-partne... |
| CVE-2025-48304 | HIGH | 7.1 | 0.1% | Aug 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin gn-xml-sitemap allows Stor... |
| CVE-2025-48109 | HIGH | 7.1 | 0.1% | Aug 28, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Xavier Media XM-Backup xm-backup allows Stored XSS.This issue affects... |
| CVE-2025-48963 | HIGH | 7.3 | 0.1% | Aug 28, 2025 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec... |
| CVE-2025-58081 | HIGH | 8.7 | 0.4% | Aug 28, 2025 | Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allo... |
| CVE-2025-58072 | HIGH | 8.7 | 0.6% | Aug 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear... |
| CVE-2025-54819 | HIGH | 7.1 | 0.4% | Aug 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear... |
| CVE-2025-53396 | HIGH | 7.3 | 0.1% | Aug 28, 2025 | Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.... |
| CVE-2025-46409 | HIGH | 8.7 | 0.2% | Aug 28, 2025 | Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If thi... |
| CVE-2025-58322 | HIGH | 7.8 | 0.1% | Aug 28, 2025 | NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM ... |
| CVE-2025-7812 | HIGH | 8.8 | 0.2% | Aug 28, 2025 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-40779 | HIGH | 7.5 | 0.5% | Aug 27, 2025 | If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the clien... |
| CVE-2025-55618 | HIGH | 7.3 | 0.2% | Aug 27, 2025 | In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field i... |
| CVE-2025-4225 | HIGH | 7.5 | 0.3% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.... |
| CVE-2025-58218 | HIGH | 7.2 | 0.4% | Aug 27, 2025 | Deserialization of Untrusted Data vulnerability in enituretechnology Small Package Quotes – USPS Edition small-package-q... |
| CVE-2025-58217 | HIGH | 7.1 | 0.1% | Aug 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News instant-breaking-news allows Stored... |
| CVE-2025-55422 | HIGH | 8.8 | 0.4% | Aug 27, 2025 | In FoxCMS 1.2.6, there is a reflected Cross Site Scripting (XSS) vulnerability in /index.php/plus. |
| CVE-2025-51667 | HIGH | 7 | 0.2% | Aug 27, 2025 | An issue was discovered in simple-admin-core v1.2.0 thru v1.6.7. The /sys-api/role/update interface in the simple-admin-... |
| CVE-2025-50979 | HIGH | 8.6 | 8.1% | Aug 27, 2025 | NodeBB v4.3.0 is vulnerable to SQL injection in its search-categories API endpoint (/api/v3/search/categories). The sear... |
| CVE-2025-34161 | HIGH | 8.8 | 3.7% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.7 are vulnerable to a remote code execution vulnerability in the project deplo... |
| CVE-2025-34159 | HIGH | 8.8 | 0.9% | Aug 27, 2025 | Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application d... |
| CVE-2025-20344 | HIGH | 7.2 | 0.5% | Aug 27, 2025 | A vulnerability in the backup restore functionality of Cisco Nexus Dashboard could allow an authenticated, remote attack... |
| CVE-2025-20317 | HIGH | 7.1 | 0.5% | Aug 27, 2025 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll... |
| CVE-2025-20241 | HIGH | 7.4 | 0.3% | Aug 27, 2025 | A vulnerability in the Intermediate System-to-Intermediate System (IS-IS) feature of Cisco NX-OS Software for Cisco Nexu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now