2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-52712 | MEDIUM | 4.2 | 0.2% | Aug 14, 2025 | Path Traversal: '.../...//' vulnerability in BoldGrid Post and Page Builder by BoldGrid post-and-page-builder allows Pat... |
| CVE-2025-50040 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in moshensky CF7 Spre... |
| CVE-2025-50031 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Missing Authorization vulnerability in syedamirhussain91 DB Backup db-backup allows Exploiting Incorrectly Configured Ac... |
| CVE-2025-50029 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Missing Authorization vulnerability in Ashish AI Tools artificial-intelligence-auto-content-generator allows Exploiting ... |
| CVE-2025-49437 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in worstguy WP LOL Ro... |
| CVE-2025-49433 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThanhD Supermalink... |
| CVE-2025-49061 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in perteus Porn Video... |
| CVE-2025-49053 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in kadesthemes WP Air... |
| CVE-2025-49052 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in Dariolee Netease Music netease-music allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-49051 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biscia7 Hide Text ... |
| CVE-2025-49048 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in inspectlet Inspect... |
| CVE-2025-49047 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in keeross DigitalOce... |
| CVE-2025-47610 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wetail WooCommerce... |
| CVE-2025-39483 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injecti... |
| CVE-2025-30993 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Missing Authorization vulnerability in VillaTheme Thank You Page Customizer for WooCommerce woo-thank-you-page-customize... |
| CVE-2025-28987 | MEDIUM | 6.4 | 0.2% | Aug 14, 2025 | Server-Side Request Forgery (SSRF) vulnerability in PressForward PressForward pressforward allows Server Side Request Fo... |
| CVE-2025-28962 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Missing Authorization vulnerability in stefanoai Advanced Google Universal Analytics advanced-google-universal-analytics... |
| CVE-2025-7761 | MEDIUM | 5.1 | 0.4% | Aug 14, 2025 | Lepszy BIP is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in index.php form in one of ... |
| CVE-2025-5998 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | The PPWP – Password Protect Pages WordPress plugin before version 1.9.11 allows to put the site content behind a passwor... |
| CVE-2025-48861 | MEDIUM | 5.3 | 0.3% | Aug 14, 2025 | A vulnerability in the Task API endpoint of the ctrlX OS setup mechanism allowed a remote, unauthenticated attacker to a... |
| CVE-2025-8046 | MEDIUM | 6.1 | 0.2% | Aug 14, 2025 | The Injection Guard WordPress plugin before 1.2.8 does not escape the $_SERVER['REQUEST_URI'] parameter before outputtin... |
| CVE-2025-7808 | MEDIUM | 6.1 | 0.2% | Aug 14, 2025 | The WP Shopify WordPress plugin before 1.5.4 does not sanitise and escape a parameter before outputting it back in the p... |
| CVE-2025-6790 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | The Quiz and Survey Master (QSM) WordPress plugin before 10.2.3 does not have CSRF check in place when updating its set... |
| CVE-2025-3414 | MEDIUM | 5.4 | 0.2% | Aug 14, 2025 | The Structured Content (JSON-LD) #wpsc WordPress plugin before 1.7.0 does not validate and escape some of its block opti... |
| CVE-2025-8938 | MEDIUM | 6.3 | 0.3% | Aug 14, 2025 | A vulnerability was found in TOTOLINK N350R 1.2.3-B20130826. This issue affects the function formSysTel of the file /boa... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now