2025 CVE Vulnerabilities
45,172 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50128 | MEDIUM | 6.1 | 0.8% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVide... |
| CVE-2025-47061 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46996 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46993 | MEDIUM | 5.4 | 0.3% | Jul 24, 2025 | Adobe Experience Manager versions 6.5.22 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability t... |
| CVE-2025-46410 | MEDIUM | 6.1 | 0.8% | Jul 24, 2025 | A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality o... |
| CVE-2025-8114 | MEDIUM | 4.7 | 0.2% | Jul 24, 2025 | A flaw was found in libssh, a library that implements the SSH protocol. When calculating the session ID during the key e... |
| CVE-2025-51089 | MEDIUM | 6.5 | 5.5% | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain heap overflow at /goform/GetParentControlInfo.The manipulation of th... |
| CVE-2025-51088 | MEDIUM | 5.3 | 6.8% | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/WifiGuestSet. The manipulation of the argu... |
| CVE-2025-51085 | MEDIUM | 5.3 | 6.8% | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/SetSysTimeCfg. The manipulation of the arg... |
| CVE-2025-51082 | MEDIUM | 5.3 | 0.5% | Jul 24, 2025 | Tenda AC8V4 V16.03.34.06` was discovered to contain stack overflow at /goform/fast_setting_wifi_set. The manipulation of... |
| CVE-2025-36005 | MEDIUM | 6.5 | 0.2% | Jul 24, 2025 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ... |
| CVE-2025-33013 | MEDIUM | 5.5 | 0.1% | Jul 24, 2025 | IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, ... |
| CVE-2025-45731 | MEDIUM | 6.5 | 0.3% | Jul 24, 2025 | A group deletion race condition in 2FAuth v5.5.0 causes data inconsistencies and orphaned accounts when a group is delet... |
| CVE-2025-40680 | MEDIUM | 6.9 | 0.1% | Jul 24, 2025 | Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and ... |
| CVE-2025-8071 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | Mine CloudVod plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘audio’ parameter in all version... |
| CVE-2025-7966 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The Get Youtube Subs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘channel', 'layout', and ... |
| CVE-2025-7959 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter... |
| CVE-2025-7835 | MEDIUM | 4.3 | 0.2% | Jul 24, 2025 | The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up t... |
| CVE-2025-7822 | MEDIUM | 4.3 | 0.3% | Jul 24, 2025 | The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability c... |
| CVE-2025-7780 | MEDIUM | 6.5 | 0.5% | Jul 24, 2025 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including,... |
| CVE-2025-7690 | MEDIUM | 6.1 | 0.2% | Jul 24, 2025 | The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-6588 | MEDIUM | 6.1 | 0.4% | Jul 24, 2025 | The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all ... |
| CVE-2025-6539 | MEDIUM | 6.4 | 0.3% | Jul 24, 2025 | The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all ... |
| CVE-2025-6387 | MEDIUM | 6.4 | 0.4% | Jul 24, 2025 | The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all ve... |
| CVE-2025-6385 | MEDIUM | 6.4 | 0.3% | Jul 24, 2025 | The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versio... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now