2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8508 | MEDIUM | 5.4 | 0.3% | Aug 3, 2025 | A vulnerability was found in Portabilis i-Educar 2.9. It has been declared as problematic. Affected by this vulnerabilit... |
| CVE-2025-8507 | MEDIUM | 5.4 | 0.3% | Aug 3, 2025 | A vulnerability was found in Portabilis i-Educar 2.9. It has been classified as problematic. Affected is an unknown func... |
| CVE-2025-8505 | MEDIUM | 4.3 | 0.2% | Aug 3, 2025 | A vulnerability has been found in 495300897 wx-shop up to de1b66331368695779cfc6e4d11a64caddf8716e and classified as pro... |
| CVE-2025-8501 | MEDIUM | 5.4 | 0.3% | Aug 3, 2025 | A vulnerability classified as problematic has been found in code-projects Human Resource Integrated System 1.0. Affected... |
| CVE-2025-52133 | MEDIUM | 6.4 | 0.2% | Aug 3, 2025 | The Mocca Calendar application before 2.15 for XWiki allows XSS via a title upon calendar import. |
| CVE-2025-52132 | MEDIUM | 6.4 | 0.2% | Aug 3, 2025 | The Mocca Calendar application before 2.15 for XWiki allows XSS via a title to the view event page. |
| CVE-2025-52131 | MEDIUM | 6.4 | 0.2% | Aug 3, 2025 | The Mocca Calendar application before 2.15 for XWiki allows XSS via the background or text color field. |
| CVE-2025-54350 | MEDIUM | 5.3 | 0.4% | Aug 3, 2025 | In iperf before 3.19.1, iperf_auth.c has a Base64Decode assertion failure and application exit upon a malformed authenti... |
| CVE-2025-23285 | MEDIUM | 5.5 | 0.1% | Aug 2, 2025 | NVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where it allows a guest to access global resou... |
| CVE-2025-23286 | MEDIUM | 4.4 | 0.1% | Aug 2, 2025 | NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an attacker could read invalid memory. A ... |
| CVE-2025-7500 | MEDIUM | 6.4 | 0.3% | Aug 2, 2025 | The Ocean Social Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via social icon titles in all... |
| CVE-2025-8488 | MEDIUM | 4.3 | 0.2% | Aug 2, 2025 | The Ultimate Addons for Elementor (Formerly Elementor Header & Footer Builder) plugin for WordPress is vulnerable to una... |
| CVE-2025-6722 | MEDIUM | 5.3 | 0.3% | Aug 2, 2025 | The BitFire Security – Firewall, WAF, Bot/Spam Blocker, Login Security plugin for WordPress is vulnerable to Sensitive I... |
| CVE-2025-8400 | MEDIUM | 6.1 | 0.2% | Aug 2, 2025 | The Image Gallery plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and includ... |
| CVE-2025-8399 | MEDIUM | 6.4 | 0.2% | Aug 2, 2025 | The Mmm Unity Loader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘attributes’ parameter in... |
| CVE-2025-8391 | MEDIUM | 6.4 | 0.2% | Aug 2, 2025 | The Magic Edge – Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in al... |
| CVE-2025-6832 | MEDIUM | 6.1 | 0.2% | Aug 2, 2025 | The All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier plugin for WordPress is vulnerable to Refl... |
| CVE-2025-8317 | MEDIUM | 6.4 | 0.2% | Aug 2, 2025 | The Custom Word Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘angle’ parameter in all... |
| CVE-2025-8212 | MEDIUM | 6.4 | 0.2% | Aug 2, 2025 | The Medical Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typew... |
| CVE-2025-8152 | MEDIUM | 5.3 | 0.3% | Aug 2, 2025 | The WP CTA – Call To Action Plugin, Sticky CTA, Sticky Buttons plugin for WordPress is vulnerable to unauthorized modifi... |
| CVE-2025-6626 | MEDIUM | 4.4 | 0.2% | Aug 2, 2025 | The ShortPixel Adaptive Images – WebP, AVIF, CDN, Image Optimization plugin for WordPress is vulnerable to Stored Cross-... |
| CVE-2025-4588 | MEDIUM | 6.4 | 0.2% | Aug 2, 2025 | The 360 Photo Spheres plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sphere' shortc... |
| CVE-2025-8146 | MEDIUM | 6.4 | 0.2% | Aug 2, 2025 | The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's TypeOut T... |
| CVE-2025-6078 | MEDIUM | 5.4 | 0.3% | Aug 2, 2025 | Partner Software's Partner Software application and Partner Web application allows an authenticated user to add notes on... |
| CVE-2025-54790 | MEDIUM | 6.5 | 0.3% | Aug 2, 2025 | Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now