2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49389 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WEN Solutions Noti... |
| CVE-2025-47650 | MEDIUM | 6.5 | 0.4% | Aug 20, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global... |
| CVE-2025-28977 | MEDIUM | 6.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes... |
| CVE-2025-9202 | MEDIUM | 4.3 | 0.2% | Aug 20, 2025 | The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2025-8618 | MEDIUM | 6.4 | 0.2% | Aug 20, 2025 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-55706 | MEDIUM | 5.1 | 0.2% | Aug 20, 2025 | URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, a... |
| CVE-2025-54551 | MEDIUM | 5.3 | 0.2% | Aug 20, 2025 | Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control... |
| CVE-2025-53522 | MEDIUM | 6.9 | 0.2% | Aug 20, 2025 | Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be ... |
| CVE-2025-57791 | MEDIUM | 6.5 | 20.7% | Aug 20, 2025 | A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments... |
| CVE-2025-57789 | MEDIUM | 5.4 | 1.1% | Aug 20, 2025 | During the brief window between installation and the first administrator login, remote attackers may exploit the default... |
| CVE-2025-57788 | MEDIUM | 6.5 | 2.7% | Aug 20, 2025 | A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user ... |
| CVE-2025-54364 | MEDIUM | 6.9 | 0.3% | Aug 20, 2025 | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_des... |
| CVE-2025-54363 | MEDIUM | 6.9 | 0.4% | Aug 20, 2025 | Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_fu... |
| CVE-2025-9171 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A security flaw has been discovered in SolidInvoice up to 2.4.0. The impacted element is an unknown function of the file... |
| CVE-2025-9170 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A vulnerability was identified in SolidInvoice up to 2.4.0. The affected element is an unknown function of the file /tax... |
| CVE-2025-9169 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A vulnerability was determined in SolidInvoice up to 2.4.0. Impacted is an unknown function of the file /quotes of the c... |
| CVE-2025-9186 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability was fixed in Firefox 142. |
| CVE-2025-9183 | MEDIUM | 6.5 | 0.2% | Aug 19, 2025 | Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 142 and Firefox ESR 140.2. |
| CVE-2025-9181 | MEDIUM | 6.5 | 0.3% | Aug 19, 2025 | Uninitialized memory in the JavaScript Engine component. This vulnerability was fixed in Firefox 142, Firefox ESR 128.14... |
| CVE-2025-9168 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A vulnerability was found in SolidInvoice up to 2.4.0. This issue affects some unknown processing of the file /invoice o... |
| CVE-2025-9167 | MEDIUM | 5.4 | 0.3% | Aug 19, 2025 | A vulnerability has been found in SolidInvoice up to 2.4.0. This vulnerability affects unknown code of the file /invoice... |
| CVE-2025-8364 | MEDIUM | 4.3 | 0.2% | Aug 19, 2025 | A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack.... |
| CVE-2025-8041 | MEDIUM | 5.3 | 0.3% | Aug 19, 2025 | In the address bar, Firefox for Android truncated the display of URLs from the end instead of prioritizing the origin. T... |
| CVE-2025-55033 | MEDIUM | 6.1 | 0.2% | Aug 19, 2025 | Dragging JavaScript links to the URL bar in Focus for iOS could be utilized to run malicious scripts, potentially result... |
| CVE-2025-55032 | MEDIUM | 6.1 | 0.1% | Aug 19, 2025 | Focus for iOS would not respect a Content-Disposition header of type Attachment and would incorrectly display the conten... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now