2025 CVE Vulnerabilities
45,342 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48297 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simpl... |
| CVE-2025-48296 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup UpStore u... |
| CVE-2025-48171 | HIGH | 8.1 | 0.4% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48170 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Unive... |
| CVE-2025-48168 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Apoll... |
| CVE-2025-48165 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in DELUCKS DELUCKS SEO delucks-seo allows Privilege Escalation.This issue a... |
| CVE-2025-48164 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in Brainstorm Force SureDash suredash allows Privilege Escalation.This issu... |
| CVE-2025-48163 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup SHOUT... |
| CVE-2025-48162 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in quantumcloud Simpl... |
| CVE-2025-48160 | HIGH | 8.1 | 0.5% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48159 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Youtu... |
| CVE-2025-48158 | HIGH | 8.6 | 0.4% | Aug 20, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Alex Githatu BuddyPress ... |
| CVE-2025-48157 | HIGH | 8.1 | 2.0% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48154 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Multi... |
| CVE-2025-48152 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dimafreund Rentsys... |
| CVE-2025-48151 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut... |
| CVE-2025-48149 | HIGH | 8.1 | 0.5% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48142 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affect... |
| CVE-2025-30975 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes al... |
| CVE-2025-57790 | HIGH | 8.8 | 16.1% | Aug 20, 2025 | A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access thr... |
| CVE-2025-8289 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and... |
| CVE-2025-8145 | HIGH | 8.8 | 0.5% | Aug 20, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and... |
| CVE-2025-8141 | HIGH | 8.8 | 0.6% | Aug 20, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil... |
| CVE-2025-9132 | HIGH | 8.8 | 3.0% | Aug 20, 2025 | Out of bounds write in V8 in Google Chrome prior to 139.0.7258.138 allowed a remote attacker to potentially exploit heap... |
| CVE-2025-9176 | HIGH | 7.8 | 1.3% | Aug 20, 2025 | A security flaw has been discovered in neurobin shc up to 4.0.3. Impacted is the function make of the file src/shc.c of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now