2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-6986 | MEDIUM | 6.5 | 0.3% | Aug 6, 2025 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via th... |
| CVE-2025-6690 | MEDIUM | 6.4 | 0.2% | Aug 6, 2025 | The WP Tournament Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘field’ paramet... |
| CVE-2025-6259 | MEDIUM | 6.4 | 0.2% | Aug 6, 2025 | The esri-map-view plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's esri-map-view short... |
| CVE-2025-6256 | MEDIUM | 6.4 | 0.3% | Aug 6, 2025 | The Flex Guten plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘thumbnailHoverEffect’ paramete... |
| CVE-2025-54623 | MEDIUM | 6.5 | 0.1% | Aug 6, 2025 | Out-of-bounds read vulnerability in the devicemanager module. Impact: Successful exploitation of this vulnerability may ... |
| CVE-2025-54620 | MEDIUM | 5.5 | 0.1% | Aug 6, 2025 | Deserialization vulnerability of untrusted data in the ability module. Impact: Successful exploitation of this vulnerabi... |
| CVE-2025-54618 | MEDIUM | 5.7 | 0.1% | Aug 6, 2025 | Permission control vulnerability in the distributed clipboard module. Impact: Successful exploitation of this vulnerabil... |
| CVE-2025-54616 | MEDIUM | 5.5 | 0.1% | Aug 6, 2025 | Out-of-bounds array access vulnerability in the ArkUI framework. Impact: Successful exploitation of this vulnerability m... |
| CVE-2025-54615 | MEDIUM | 5.5 | 0.1% | Aug 6, 2025 | Vulnerability of insufficient information protection in the media library module. Impact: Successful exploitation of thi... |
| CVE-2025-54614 | MEDIUM | 5.5 | 0.1% | Aug 6, 2025 | Input verification vulnerability in the home screen module. Impact: Successful exploitation of this vulnerability may af... |
| CVE-2025-54611 | MEDIUM | 5.5 | 0.1% | Aug 6, 2025 | EXTRA_REFERRER resource read vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability ... |
| CVE-2025-54608 | MEDIUM | 4 | 0.1% | Aug 6, 2025 | Vulnerability that allows setting screen rotation direction without permission verification in the screen management mod... |
| CVE-2025-54653 | MEDIUM | 6.5 | 0.1% | Aug 6, 2025 | Path traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect... |
| CVE-2025-54652 | MEDIUM | 5.5 | 0.1% | Aug 6, 2025 | Path traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect... |
| CVE-2025-54876 | MEDIUM | 6.9 | 0.4% | Aug 6, 2025 | The Janssen Project is an open-source identity and access management (IAM) platform. In versions 1.9.0 and below, Jansse... |
| CVE-2025-54869 | MEDIUM | 6 | 0.3% | Aug 6, 2025 | FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template... |
| CVE-2025-54571 | MEDIUM | 6.1 | 0.3% | Aug 6, 2025 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versio... |
| CVE-2025-54125 | MEDIUM | 6.5 | 1.2% | Aug 6, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ... |
| CVE-2025-54124 | MEDIUM | 6.5 | 0.4% | Aug 6, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform ... |
| CVE-2025-32430 | MEDIUM | 6.1 | 0.6% | Aug 6, 2025 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions 4.2... |
| CVE-2025-8573 | MEDIUM | 4.8 | 0.4% | Aug 5, 2025 | Concrete CMS versions 9 through 9.4.2 are vulnerable to Stored XSS from Home Folder on Members Dashboard page. Version ... |
| CVE-2025-8571 | MEDIUM | 4.8 | 0.3% | Aug 5, 2025 | Concrete CMS 9 to 9.4.2 and versions below 8.5.21 are vulnerable to Reflected Cross-Site Scripting (XSS) in the Conversa... |
| CVE-2025-52237 | MEDIUM | 6.5 | 0.5% | Aug 5, 2025 | An issue in the component /stl/actions/download?filePath of SSCMS v7.3.1 allows attackers to execute a directory travers... |
| CVE-2025-52078 | MEDIUM | 6.5 | 0.4% | Aug 5, 2025 | File upload vulnerability in Writebot AI Content Generator SaaS React Template thru 4.0.0, allowing remote attackers to ... |
| CVE-2025-51541 | MEDIUM | 6.1 | 0.4% | Aug 5, 2025 | A stored cross-site scripting (XSS) vulnerability exists in the Shopware 6 installation interface at /recovery/install/d... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now