2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9228 | MEDIUM | 4.3 | 0.2% | Aug 20, 2025 | MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowin... |
| CVE-2025-9225 | MEDIUM | 5.5 | 0.2% | Aug 20, 2025 | Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fle... |
| CVE-2025-54053 | MEDIUM | 6.6 | 0.3% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue... |
| CVE-2025-54046 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Cost ... |
| CVE-2025-54040 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Missing Authorization vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Exploiting Inco... |
| CVE-2025-54025 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Missing Authorization vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Exploiting Inc... |
| CVE-2025-54019 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injectio... |
| CVE-2025-54008 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetSmartFilters jet-smart-filters allows R... |
| CVE-2025-53998 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetWooBuilder jet-woo-builder allows Retri... |
| CVE-2025-53993 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetPopup jet-popup allows Retrieve Embedde... |
| CVE-2025-53992 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTricks jet-tricks allows Retrieve Embed... |
| CVE-2025-53988 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetBlocks For Elementor jet-blocks allows ... |
| CVE-2025-53987 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetMenu jet-menu allows Retrieve Embedded ... |
| CVE-2025-53985 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetTabs jet-tabs allows Retrieve Embedded ... |
| CVE-2025-53983 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetElements For Elementor jet-elements all... |
| CVE-2025-53561 | MEDIUM | 6.5 | 0.4% | Aug 20, 2025 | Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path T... |
| CVE-2025-53196 | MEDIUM | 6.5 | 0.5% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Crocoblock JetEngine jet-engine allows Retrieve Embed... |
| CVE-2025-53195 | MEDIUM | 6.5 | 0.3% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi... |
| CVE-2025-49896 | MEDIUM | 5.3 | 0.2% | Aug 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows C... |
| CVE-2025-49412 | MEDIUM | 5.9 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in numixtech Page Tra... |
| CVE-2025-49397 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Colorbox... |
| CVE-2025-49396 | MEDIUM | 4.3 | 0.2% | Aug 20, 2025 | Missing Authorization vulnerability in themifyme Themify Builder themify-builder allows Exploiting Incorrectly Configure... |
| CVE-2025-49395 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ... |
| CVE-2025-49392 | MEDIUM | 5.9 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in themifyme Themify ... |
| CVE-2025-49391 | MEDIUM | 4.3 | 0.1% | Aug 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Cross Site Request... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now