2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8720 | MEDIUM | 6.4 | 0.2% | Aug 15, 2025 | The Plugin README Parser plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘target’ parameter in... |
| CVE-2025-8091 | MEDIUM | 4.3 | 0.4% | Aug 15, 2025 | The EventON Lite plugin for WordPress is vulnerable to Information Exposure in all versions less than, or equal to, 2.4.... |
| CVE-2025-8080 | MEDIUM | 4.4 | 0.2% | Aug 15, 2025 | The Alobaidi Captcha plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin settings in all ve... |
| CVE-2025-7688 | MEDIUM | 6.1 | 0.1% | Aug 15, 2025 | The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2025-7662 | MEDIUM | 6.5 | 0.3% | Aug 15, 2025 | The Gestion de tarifs plugin for WordPress is vulnerable to SQL Injection via the 'tarif' and 'intitule' shortcodes in a... |
| CVE-2025-7507 | MEDIUM | 6.4 | 0.2% | Aug 15, 2025 | The elink – Embed Content plugin for WordPress is vulnerable to Malicious Redirect in all versions up to, and including,... |
| CVE-2025-5844 | MEDIUM | 6.4 | 0.2% | Aug 15, 2025 | The Radius Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘subHeadingTagName’ paramete... |
| CVE-2025-9020 | MEDIUM | 4.5 | 0.1% | Aug 15, 2025 | A vulnerability was found in PX4 PX4-Autopilot up to 1.15.4. This issue affects the function MavlinkReceiver::handle_mes... |
| CVE-2025-8604 | MEDIUM | 6.4 | 0.3% | Aug 15, 2025 | The WP Table Builder – WordPress Table Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ... |
| CVE-2025-9019 | MEDIUM | 5.9 | 0.9% | Aug 15, 2025 | A vulnerability has been found in tcpreplay 4.5.1. This vulnerability affects the function mask_cidr6 of the file cidr.c... |
| CVE-2025-9017 | MEDIUM | 6.1 | 0.3% | Aug 15, 2025 | A vulnerability has been found in PHPGurukul Zoo Management System 2.1. This vulnerability affects unknown code of the f... |
| CVE-2025-8451 | MEDIUM | 6.4 | 0.2% | Aug 15, 2025 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to DOM-Bas... |
| CVE-2025-31961 | MEDIUM | 4.6 | 0.1% | Aug 15, 2025 | HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai... |
| CVE-2025-9003 | MEDIUM | 5.4 | 0.6% | Aug 15, 2025 | A vulnerability has been found in D-Link DIR-818LW 1.04. This vulnerability affects unknown code of the file /bsc_lan.ph... |
| CVE-2025-8867 | MEDIUM | 6.4 | 0.4% | Aug 15, 2025 | The Graphina - Elementor Charts and Graphs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multipl... |
| CVE-2025-8680 | MEDIUM | 4.3 | 0.3% | Aug 15, 2025 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Server-Side Request Forgery in version... |
| CVE-2025-8676 | MEDIUM | 4.3 | 0.3% | Aug 15, 2025 | The B Slider- Gutenberg Slider Block for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in vers... |
| CVE-2025-8992 | MEDIUM | 6.5 | 0.2% | Aug 15, 2025 | A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The man... |
| CVE-2025-8991 | MEDIUM | 4.3 | 0.3% | Aug 15, 2025 | A vulnerability was identified in linlinjava litemall up to 1.8.0. Affected by this vulnerability is an unknown function... |
| CVE-2025-8980 | MEDIUM | 6.6 | 0.3% | Aug 14, 2025 | A vulnerability has been found in Tenda G1 16.01.7.8(3660). Affected by this issue is the function check_upload_file of ... |
| CVE-2025-8979 | MEDIUM | 6.6 | 0.4% | Aug 14, 2025 | A vulnerability was identified in Tenda AC15 15.13.07.13. Affected by this vulnerability is the function check_fw_type/s... |
| CVE-2025-51965 | MEDIUM | 6.1 | 0.2% | Aug 14, 2025 | OURPHP thru 8.6.1 is vulnerable to Cross-Site Scripting (XSS) via the "Name" field of the "Complete Profile" functionali... |
| CVE-2025-50862 | MEDIUM | 5.9 | 0.1% | Aug 14, 2025 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 has allowBackup=true set in its manifest, allowing data e... |
| CVE-2025-50861 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | The Lotus Cars Android app (com.lotus.carsdomestic.intl) 1.2.8 contains an exported component, PushDeepLinkActivity, whi... |
| CVE-2025-8976 | MEDIUM | 5.4 | 0.3% | Aug 14, 2025 | A vulnerability has been found in givanz Vvveb up to 1.0.5. This vulnerability affects unknown code of the file /vadmin1... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now