2025 CVE Vulnerabilities
45,169 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58797 | MEDIUM | 5.3 | 0.3% | Sep 5, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Mahmudul Hasan Arif Ninja Ch... |
| CVE-2025-58796 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dudaster Elementor... |
| CVE-2025-58795 | MEDIUM | 4.3 | 0.2% | Sep 5, 2025 | Missing Authorization vulnerability in Payoneer Checkout Payoneer Checkout payoneer-checkout allows Content Spoofing.Thi... |
| CVE-2025-58794 | MEDIUM | 4.3 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in rainafarai Notification for Telegram notification-for-telegram allows... |
| CVE-2025-58793 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBean WPB Element... |
| CVE-2025-58792 | MEDIUM | 4.3 | 0.1% | Sep 5, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WPKube Authors List authors-list allows Cross Site Request Forgery.Th... |
| CVE-2025-58791 | MEDIUM | 5.9 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Arjan Olsder SEO A... |
| CVE-2025-58790 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKube Kiwi kiwi-s... |
| CVE-2025-58787 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ... |
| CVE-2025-58786 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VW THEMES Ibtana –... |
| CVE-2025-58785 | MEDIUM | 5.4 | 0.2% | Sep 5, 2025 | Missing Authorization vulnerability in Jiro Sasamoto Ray Enterprise Translation lingotek-translation allows Exploiting I... |
| CVE-2025-58784 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in arisoft ARI Fancy ... |
| CVE-2025-58783 | MEDIUM | 4.3 | 0.2% | Sep 5, 2025 | Missing Authorization vulnerability in gutentor Gutentor gutentor allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2025-58296 | MEDIUM | 4.7 | 0.1% | Sep 5, 2025 | Race condition vulnerability in the audio module. Impact: Successful exploitation of this vulnerability may affect funct... |
| CVE-2025-58281 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | Out-of-bounds read vulnerability in the runtime interpreter module. Impact: Successful exploitation of this vulnerabilit... |
| CVE-2025-58280 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | Vulnerability of exposing object heap addresses in the Ark eTS module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2025-58276 | MEDIUM | 5.5 | 0.1% | Sep 5, 2025 | Permission verification vulnerability in the home screen module Impact: Successful exploitation of this vulnerability ma... |
| CVE-2025-48395 | MEDIUM | 4.7 | 0.3% | Sep 5, 2025 | An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the... |
| CVE-2025-8944 | MEDIUM | 4.3 | 0.2% | Sep 5, 2025 | The OceanWP WordPress theme before 4.1.2 is vulnerable to an option update due to a missing capability check on one of i... |
| CVE-2025-41408 | MEDIUM | 5.3 | 0.3% | Sep 5, 2025 | Improper authorization in handler for custom URL scheme issue in "Yahoo! Shopping" App for Android versions prior to 14.... |
| CVE-2025-58401 | MEDIUM | 6.8 | 0.1% | Sep 5, 2025 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacke... |
| CVE-2025-8684 | MEDIUM | 6.4 | 0.2% | Sep 5, 2025 | The Flatsome Theme for WordPress is vulnerable to Stored Cross-Site Scripting via the theme's shortcodes in all versions... |
| CVE-2025-7445 | MEDIUM | 6.5 | 0.2% | Sep 5, 2025 | Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs. |
| CVE-2025-58359 | MEDIUM | 6 | 0.3% | Sep 5, 2025 | ZF FROST is a Rust implementation of FROST (Flexible Round-Optimised Schnorr Threshold signatures). In versions 2.0.0 th... |
| CVE-2025-58352 | MEDIUM | 6.5 | 0.3% | Sep 5, 2025 | Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session ex... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now