2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8113 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting i... |
| CVE-2025-8293 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in... |
| CVE-2025-7686 | MEDIUM | 6.1 | 0.1% | Aug 16, 2025 | The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-7684 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-7683 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-7668 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-7651 | MEDIUM | 6.4 | 0.3% | Aug 16, 2025 | The Earnware Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ew_hasrole' sho... |
| CVE-2025-7649 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-7440 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']... |
| CVE-2025-7439 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link... |
| CVE-2025-6221 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versi... |
| CVE-2025-49895 | MEDIUM | 6.5 | 0.1% | Aug 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This i... |
| CVE-2025-52620 | MEDIUM | 5.4 | 0.2% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a Cross-Site Scripting (XSS) vulnerability. The image upload func... |
| CVE-2025-52619 | MEDIUM | 5.3 | 0.3% | Aug 15, 2025 | HCL BigFix SaaS Authentication Service is affected by a sensitive information disclosure. Under certain conditions, err... |
| CVE-2025-43201 | MEDIUM | 6.2 | 0.1% | Aug 15, 2025 | This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may ... |
| CVE-2025-36088 | MEDIUM | 5.4 | 0.2% | Aug 15, 2025 | IBM TS4500 1.11.0.0-D00, 1.11.0.1-C00, 1.11.0.2-C00, and 1.10.00-F00 web GUI is vulnerable to cross-site scripting. This... |
| CVE-2025-8996 | MEDIUM | 4.3 | 0.2% | Aug 15, 2025 | Missing Authorization vulnerability in Drupal Layout Builder Advanced Permissions allows Forceful Browsing.This issue af... |
| CVE-2025-8362 | MEDIUM | 6.1 | 0.2% | Aug 15, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Drupal GoogleTag M... |
| CVE-2025-7961 | MEDIUM | 6.9 | 0.2% | Aug 15, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Wulkano KAP on MacOS allows TCC Bypass.This i... |
| CVE-2025-8066 | MEDIUM | 4.8 | 0.4% | Aug 15, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Bunkerity Bunker Web on Linux allows Phishing.This ... |
| CVE-2025-55207 | MEDIUM | 5.5 | 0.5% | Aug 15, 2025 | Astro is a web framework for content-driven websites. Following CVE-2025-54793 there's still an Open Redirect vulnerabil... |
| CVE-2025-49432 | MEDIUM | 5.3 | 0.3% | Aug 15, 2025 | Missing Authorization vulnerability in FWDesign Ultimate Video Player fwduvp allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-55203 | MEDIUM | 5.4 | 0.2% | Aug 15, 2025 | Plane is open-source project management software. Prior to version 0.28.0, a stored cross-site scripting (XSS) vulnerabi... |
| CVE-2025-26709 | MEDIUM | 5.7 | 0.2% | Aug 15, 2025 | There is an unauthorized access vulnerability in ZTE F50. Due to improper permission control of the Web module interface... |
| CVE-2025-8905 | MEDIUM | 6.3 | 0.3% | Aug 15, 2025 | The Inpersttion For Theme plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includi... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now