2025 CVE Vulnerabilities
45,170 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58606 | MEDIUM | 5 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in cozythemes SaasLauncher saaslauncher allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-58605 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP De... |
| CVE-2025-58603 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | Missing Authorization vulnerability in Surfer Surfer surferseo allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2025-58602 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in If-So Dynamic Cont... |
| CVE-2025-58601 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly C... |
| CVE-2025-58600 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting ... |
| CVE-2025-58599 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocom... |
| CVE-2025-58598 | MEDIUM | 6.6 | 0.2% | Sep 3, 2025 | Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce k... |
| CVE-2025-58597 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorre... |
| CVE-2025-58596 | MEDIUM | 5.9 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction Mai... |
| CVE-2025-58594 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-58593 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fo... |
| CVE-2025-58460 | MEDIUM | 4.2 | 0.2% | Sep 3, 2025 | A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Over... |
| CVE-2025-58459 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endp... |
| CVE-2025-58458 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ b... |
| CVE-2025-57149 | MEDIUM | 6.5 | 0.4% | Sep 3, 2025 | phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid paramete... |
| CVE-2025-56608 | MEDIUM | 4.2 | 0.3% | Sep 3, 2025 | The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHtt... |
| CVE-2025-9822 | MEDIUM | 5.5 | 0.2% | Sep 3, 2025 | SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that ... |
| CVE-2025-0878 | MEDIUM | 4.7 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Li... |
| CVE-2025-9901 | MEDIUM | 5.9 | 0.4% | Sep 3, 2025 | A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached... |
| CVE-2025-3701 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in Malcure Web Security Malcure Malware Scanner wp-malware-removal allows Exploiting... |
| CVE-2025-38678 | MEDIUM | 5.5 | 0.2% | Sep 3, 2025 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: reject duplicate device on up... |
| CVE-2025-9219 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | The Post SMTP – WP SMTP Plugin with Email Logs and Mobile App for Failure Notifications – Gmail SMTP, Office 365, Brevo,... |
| CVE-2025-9378 | MEDIUM | 6.4 | 0.2% | Sep 3, 2025 | The Vayu Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2025-8663 | MEDIUM | 6.5 | 0.3% | Sep 3, 2025 | Insertion of Sensitive Information into Log File vulnerability in upKeeper Solutions upKeeper Manager allows Use of Know... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now