2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58205 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Element Invader El... |
| CVE-2025-58204 | MEDIUM | 4.7 | 0.2% | Aug 27, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podc... |
| CVE-2025-58203 | MEDIUM | 4.4 | 0.2% | Aug 27, 2025 | Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forger... |
| CVE-2025-58202 | MEDIUM | 4.3 | 0.1% | Aug 27, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-acces... |
| CVE-2025-58201 | MEDIUM | 5.3 | 0.2% | Aug 27, 2025 | Missing Authorization vulnerability in AfterShip & Automizely AfterShip Tracking aftership-woocommerce-tracking allows A... |
| CVE-2025-58198 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Missing Authorization vulnerability in Xpro Xpro Theme Builder xpro-theme-builder allows Exploiting Incorrectly Configur... |
| CVE-2025-58197 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mra13 Simple Downl... |
| CVE-2025-58196 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uicore UiCore Elem... |
| CVE-2025-58195 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xpro Xpro Elemento... |
| CVE-2025-58194 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2025-58193 | MEDIUM | 4.3 | 0.2% | Aug 27, 2025 | Missing Authorization vulnerability in Uncanny Owl Uncanny Automator uncanny-automator allows Exploiting Incorrectly Con... |
| CVE-2025-58192 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | Missing Authorization vulnerability in Xylus Themes WP Bulk Delete wp-bulk-delete allows Exploiting Incorrectly Configur... |
| CVE-2025-5187 | MEDIUM | 6.7 | 0.4% | Aug 27, 2025 | A vulnerability exists in the NodeRestriction admission controller in Kubernetes clusters where node users can delete th... |
| CVE-2025-57821 | MEDIUM | 4.2 | 0.2% | Aug 27, 2025 | Basecamp's Google Sign-In adds Google sign-in to Rails applications. Prior to version 1.3.0, it is possible to craft a m... |
| CVE-2025-50977 | MEDIUM | 6.1 | 0.3% | Aug 27, 2025 | A template injection vulnerability leading to reflected cross-site scripting (XSS) has been identified in version 1.7.1,... |
| CVE-2025-20348 | MEDIUM | 5 | 0.3% | Aug 27, 2025 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co... |
| CVE-2025-20347 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A vulnerability in the REST API endpoints of Cisco Nexus Dashboard and Cisco Nexus Dashboard Fabric Controller (NDFC) co... |
| CVE-2025-20342 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controll... |
| CVE-2025-20296 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A vulnerability in the web-based management interface of Cisco UCS Manager Software could allow an authenticated, remote... |
| CVE-2025-20295 | MEDIUM | 6 | 0.2% | Aug 27, 2025 | A vulnerability in the CLI of Cisco UCS Manager Software could allow an authenticated, local attacker with administrativ... |
| CVE-2025-20294 | MEDIUM | 6.5 | 1.2% | Aug 27, 2025 | Multiple vulnerabilities in the CLI and web-based management interface of Cisco UCS Manager Software could allow an auth... |
| CVE-2025-20292 | MEDIUM | 4.4 | 3.2% | Aug 27, 2025 | A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute a command inj... |
| CVE-2025-20290 | MEDIUM | 5.5 | 0.1% | Aug 27, 2025 | A vulnerability in the logging feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches, Cisco Nexus 9000 Se... |
| CVE-2025-20262 | MEDIUM | 5 | 0.3% | Aug 27, 2025 | A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and C... |
| CVE-2025-54598 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete al... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now