2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7845 | MEDIUM | 6.4 | 0.2% | Aug 1, 2025 | The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Advan... |
| CVE-2025-4523 | MEDIUM | 6.5 | 0.3% | Aug 1, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2025-8433 | MEDIUM | 5.4 | 0.4% | Aug 1, 2025 | A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects... |
| CVE-2025-53399 | MEDIUM | 6.9 | 5.0% | Aug 1, 2025 | In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic of the media-relay core ... |
| CVE-2025-48073 | MEDIUM | 6.2 | 0.2% | Jul 31, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-23289 | MEDIUM | 5.5 | 0.1% | Jul 31, 2025 | NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause ... |
| CVE-2025-45769 | MEDIUM | 6.5 | 0.1% | Jul 31, 2025 | php-jwt v6.11.0 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key leng... |
| CVE-2025-37112 | MEDIUM | 6 | 0.1% | Jul 31, 2025 | A vulnerability was discovered in the storage policy for certain sets of encryption keys in the HPE Telco Network Functi... |
| CVE-2025-37111 | MEDIUM | 6 | 0.1% | Jul 31, 2025 | A vulnerability was discovered in the storage policy for certain sets of authentication keys in the HPE Telco Network Fu... |
| CVE-2025-37110 | MEDIUM | 6 | 0.1% | Jul 31, 2025 | A vulnerability was discovered in the storage policy for certain sets of sensitive credential information in the HPE Tel... |
| CVE-2025-54834 | MEDIUM | 6.9 | 0.5% | Jul 31, 2025 | OPEXUS FOIAXpress Public Access Link (PAL) version v11.1.0 allows an unauthenticated, remote attacker to query the /App/... |
| CVE-2025-54832 | MEDIUM | 5.3 | 0.3% | Jul 31, 2025 | OPEXUS FOIAXpress Public Access Link (PAL), version v11.1.0, allows an authenticated user to add entries to the list of ... |
| CVE-2025-50866 | MEDIUM | 6.1 | 0.3% | Jul 31, 2025 | CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of t... |
| CVE-2025-50867 | MEDIUM | 6.5 | 0.2% | Jul 31, 2025 | A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where th... |
| CVE-2025-50848 | MEDIUM | 6.1 | 0.2% | Jul 31, 2025 | A file upload vulnerability was discovered in CS Cart 4.18.3, allows attackers to execute arbitrary code. CS Cart 4.18.3... |
| CVE-2025-50847 | MEDIUM | 6.5 | 0.1% | Jul 31, 2025 | Cross Site Request Forgery (CSRF) vulnerability in CS Cart 4.18.3, allows attackers to add products to a user's comparis... |
| CVE-2025-46809 | MEDIUM | 6.9 | 0.2% | Jul 31, 2025 | A Plaintext Storage of a Password vulnerability in SUSE exposes the credentials for the HTTP proxy in the log files. Thi... |
| CVE-2025-51569 | MEDIUM | 6.1 | 0.2% | Jul 31, 2025 | A cross-site scripting (XSS) vulnerability exists in the LB-Link BL-CPE300M 01.01.02P42U14_06 router's web interface. Th... |
| CVE-2025-50270 | MEDIUM | 6.1 | 0.3% | Jul 31, 2025 | A stored Cross Site Scripting (xss) vulnerability in the "content management" feature in AnQiCMS v.3.4.11 allows a remot... |
| CVE-2025-29557 | MEDIUM | 5.4 | 0.2% | Jul 31, 2025 | ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where user... |
| CVE-2025-7738 | MEDIUM | 4.4 | 0.2% | Jul 31, 2025 | A flaw was found in Ansible Automation Platform (AAP) where the Gateway API returns the client secret for certain GitHub... |
| CVE-2025-54589 | MEDIUM | 6.1 | 2.3% | Jul 31, 2025 | Copyparty is a portable file server. In versions 1.18.6 and below, when accessing the recent uploads page at `/?ru`, use... |
| CVE-2025-8401 | MEDIUM | 4.3 | 0.3% | Jul 31, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all ... |
| CVE-2025-8151 | MEDIUM | 4.3 | 0.4% | Jul 31, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Path Traversal in all versions up to, ... |
| CVE-2025-8068 | MEDIUM | 4.3 | 0.3% | Jul 31, 2025 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to unauthorized modification and loss of ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now