2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8975 | MEDIUM | 5.4 | 0.3% | Aug 14, 2025 | A vulnerability was identified in givanz Vvveb up to 1.0.5. This affects an unknown part of the file admin/template/cont... |
| CVE-2025-55716 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in VeronaLabs WP Statistics wp-statistics allows Exploiting Incorrectly Configured A... |
| CVE-2025-55714 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem... |
| CVE-2025-55713 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in creativethemeshq B... |
| CVE-2025-55712 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elem... |
| CVE-2025-55711 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Table Builder W... |
| CVE-2025-55710 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Steve Burge TaxoPress simple-tags allows Retrieve Emb... |
| CVE-2025-55709 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Visual Composer Vi... |
| CVE-2025-54749 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetProd... |
| CVE-2025-54747 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpbakery Templater... |
| CVE-2025-54746 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cartpauj Shortcode... |
| CVE-2025-54740 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Nelson Pri... |
| CVE-2025-54739 | MEDIUM | 5.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in POSIMYTH Nexter Blocks the-plus-addons-for-block-editor allows Exploiting Incorre... |
| CVE-2025-54736 | MEDIUM | 5.3 | 0.2% | Aug 14, 2025 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in NordicMade Savoy savoy allow... |
| CVE-2025-54732 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Shahjada WPDM – Premium Packages wpdm-premium-packages allows Cross S... |
| CVE-2025-54730 | MEDIUM | 5.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in PARETO Digital Embedder for Google Reviews embedder-for-google-reviews allows Acc... |
| CVE-2025-54729 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webba Appointment ... |
| CVE-2025-54728 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CreativeMindsSolutions CM On Demand Search And Replace cm-on-demand-s... |
| CVE-2025-54727 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CreativeMindsSolut... |
| CVE-2025-54717 | MEDIUM | 5.4 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in e-plugins WP Membership wp-membership allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-54715 | MEDIUM | 4.9 | 0.4% | Aug 14, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Dmitry V. (CEO of "UKR S... |
| CVE-2025-54712 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in hashthemes Easy Elementor Addons easy-elementor-addons allows Exploiting Incorrec... |
| CVE-2025-54708 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins B Blocks ... |
| CVE-2025-54054 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AA Web Servant 12 ... |
| CVE-2025-53582 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WordLift WordLift ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now