2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8380 | MEDIUM | 5.4 | 0.3% | Jul 31, 2025 | A vulnerability classified as problematic was found in Campcodes Online Hotel Reservation System 1.0. This vulnerability... |
| CVE-2025-40980 | MEDIUM | 5.1 | 0.5% | Jul 31, 2025 | A Stored Cross Site Scripting vulnerability has been found in UltimatePOS by UltimateFosters. This vulnerability is due ... |
| CVE-2025-8192 | MEDIUM | 6.9 | 0.1% | Jul 31, 2025 | There exists a TOCTOU race condition in TvSettings AppRestrictionsFragment.java that lead to start of attacker supplied ... |
| CVE-2025-24854 | MEDIUM | 6.1 | 0.4% | Jul 31, 2025 | A carefully crafted request using the Image plugin could trigger an XSS vulnerability on Apache JSPWiki, which could al... |
| CVE-2025-7205 | MEDIUM | 5.4 | 0.2% | Jul 31, 2025 | The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2025-41396 | MEDIUM | 6.5 | 0.3% | Jul 31, 2025 | A path traversal issue exists in file uploading feature of multiple versions of PowerCMS. Arbitrary files may be overwri... |
| CVE-2025-41391 | MEDIUM | 5.4 | 0.2% | Jul 31, 2025 | Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a maliciou... |
| CVE-2025-36563 | MEDIUM | 6.1 | 0.2% | Jul 31, 2025 | Reflected cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product administrator accesse... |
| CVE-2025-8370 | MEDIUM | 6.1 | 0.5% | Jul 31, 2025 | A vulnerability, which was classified as problematic, was found in Portabilis i-Educar 2.9. Affected is an unknown funct... |
| CVE-2025-8369 | MEDIUM | 6.1 | 0.5% | Jul 31, 2025 | A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9. This issue affects some... |
| CVE-2025-8368 | MEDIUM | 6.1 | 0.5% | Jul 31, 2025 | A vulnerability classified as problematic was found in Portabilis i-Educar 2.9. This vulnerability affects unknown code ... |
| CVE-2025-8367 | MEDIUM | 6.1 | 0.4% | Jul 31, 2025 | A vulnerability classified as problematic has been found in Portabilis i-Educar 2.9. This affects an unknown part of the... |
| CVE-2025-8366 | MEDIUM | 6.1 | 0.4% | Jul 31, 2025 | A vulnerability was found in Portabilis i-Educar 2.9. It has been rated as problematic. Affected by this issue is some u... |
| CVE-2025-5720 | MEDIUM | 6.4 | 0.3% | Jul 31, 2025 | The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author’ ... |
| CVE-2025-8365 | MEDIUM | 6.1 | 0.3% | Jul 31, 2025 | A vulnerability was found in Portabilis i-Educar 2.10. It has been declared as problematic. Affected by this vulnerabili... |
| CVE-2025-8347 | MEDIUM | 6.5 | 0.3% | Jul 31, 2025 | A vulnerability, which was classified as critical, was found in Kehua Charging Pile Cloud Platform 1.0. This affects an ... |
| CVE-2025-8346 | MEDIUM | 6.1 | 0.4% | Jul 31, 2025 | A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.10. Affected by this issue... |
| CVE-2025-8340 | MEDIUM | 6.1 | 0.4% | Jul 31, 2025 | A vulnerability was found in code-projects Intern Membership Management System 1.0. It has been declared as problematic.... |
| CVE-2025-36040 | MEDIUM | 6.5 | 0.2% | Jul 31, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client... |
| CVE-2025-36039 | MEDIUM | 6.5 | 0.2% | Jul 31, 2025 | IBM Aspera Faspex 5.0.0 through 5.0.12.1 could allow an authenticated user to perform unauthorized actions due to client... |
| CVE-2025-8337 | MEDIUM | 5.4 | 0.2% | Jul 30, 2025 | A vulnerability, which was classified as problematic, has been found in code-projects Simple Car Rental System 1.0. This... |
| CVE-2025-8335 | MEDIUM | 4.3 | 0.2% | Jul 30, 2025 | A vulnerability classified as problematic has been found in code-projects Simple Car Rental System 1.0. This affects an ... |
| CVE-2025-54586 | MEDIUM | 6.5 | 0.3% | Jul 30, 2025 | GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, att... |
| CVE-2025-54585 | MEDIUM | 6.5 | 0.3% | Jul 30, 2025 | GitProxy is an application that stands between developers and a Git remote endpoint. In versions 1.19.1 and below, attac... |
| CVE-2025-54584 | MEDIUM | 5.7 | 0.5% | Jul 30, 2025 | GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). In versions 1.19... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now