2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52460 | MEDIUM | 6.9 | 0.3% | Aug 28, 2025 | Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a... |
| CVE-2025-8073 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-6255 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-7956 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in it... |
| CVE-2025-8977 | MEDIUM | 6.5 | 0.3% | Aug 28, 2025 | The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in al... |
| CVE-2025-9346 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up t... |
| CVE-2025-9345 | MEDIUM | 4.9 | 0.5% | Aug 28, 2025 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versio... |
| CVE-2025-8603 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge... |
| CVE-2025-0951 | MEDIUM | 4.3 | 0.2% | Aug 28, 2025 | Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capa... |
| CVE-2025-9352 | MEDIUM | 5.4 | 0.2% | Aug 28, 2025 | The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in ... |
| CVE-2025-9344 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2025-8897 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2025-36003 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information whe... |
| CVE-2025-34521 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection... |
| CVE-2025-5101 | MEDIUM | 5 | 0.1% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1... |
| CVE-2025-55582 | MEDIUM | 6.6 | 0.2% | Aug 27, 2025 | D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly ... |
| CVE-2025-3601 | MEDIUM | 6.5 | 0.3% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.... |
| CVE-2025-2246 | MEDIUM | 5.3 | 0.3% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1... |
| CVE-2025-55495 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind ... |
| CVE-2025-58216 | MEDIUM | 5.9 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in jgwhite33 WP Thumb... |
| CVE-2025-58213 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ameliabooking Book... |
| CVE-2025-58212 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in epeken Epeken All ... |
| CVE-2025-58211 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in alexvtn Chatbox Ma... |
| CVE-2025-58209 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in rtCamp Transcoder ... |
| CVE-2025-58208 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF fo... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now