2025 CVE Vulnerabilities
45,173 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-50057 | MEDIUM | 6.9 | 0.4% | Jul 18, 2025 | A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote a... |
| CVE-2025-50056 | MEDIUM | 5.1 | 0.4% | Jul 18, 2025 | A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote a... |
| CVE-2025-2425 | MEDIUM | 5.1 | 0.1% | Jul 18, 2025 | Time-of-check to time-of-use race condition vulnerability potentially allowed an attacker to use the installed ESET secu... |
| CVE-2025-6226 | MEDIUM | 6.5 | 0.3% | Jul 18, 2025 | Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization... |
| CVE-2025-6197 | MEDIUM | 4.2 | 3.7% | Jul 18, 2025 | An open redirect vulnerability has been identified in Grafana OSS organization switching functionality. Prerequisites ... |
| CVE-2025-7772 | MEDIUM | 6.5 | 0.3% | Jul 18, 2025 | The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F... |
| CVE-2025-6726 | MEDIUM | 4.3 | 0.2% | Jul 18, 2025 | The Block Editor Gallery Slider plugin for WordPress is vulnerable to unauthorized modification of data due to a missing... |
| CVE-2025-6719 | MEDIUM | 4.4 | 0.2% | Jul 18, 2025 | The Terms descriptions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi... |
| CVE-2025-6717 | MEDIUM | 6.5 | 0.3% | Jul 18, 2025 | The B1.lt plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and includin... |
| CVE-2025-5811 | MEDIUM | 5.3 | 0.3% | Jul 18, 2025 | The Listly: Listicles For WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a mis... |
| CVE-2025-5800 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Testimonial Post type plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘auto_play’ paramete... |
| CVE-2025-5767 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Crowdfunding for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width’ param... |
| CVE-2025-5754 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Useful Tab Block – Responsive & AMP-Compatible plugin for WordPress is vulnerable to Stored Cross-Site Scripting via... |
| CVE-2025-5752 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Vertical scroll image slideshow gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘w... |
| CVE-2025-7660 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Map My Locations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'map_my_location... |
| CVE-2025-7648 | MEDIUM | 6.4 | 0.2% | Jul 18, 2025 | The Ruven Themes: Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ruven_b... |
| CVE-2025-7638 | MEDIUM | 4.9 | 0.3% | Jul 18, 2025 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to time-based... |
| CVE-2025-6781 | MEDIUM | 4.3 | 0.1% | Jul 18, 2025 | The Copymatic – AI Content Writer & Generator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all ve... |
| CVE-2025-6053 | MEDIUM | 6.1 | 0.1% | Jul 18, 2025 | The Zuppler Online Ordering plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and ... |
| CVE-2025-5816 | MEDIUM | 4.3 | 0.2% | Jul 18, 2025 | The Plugin Pengiriman WooCommerce Kurir Reguler, Instan, Kargo – Biteship plugin for WordPress is vulnerable to Insecure... |
| CVE-2025-7431 | MEDIUM | 4.4 | 0.2% | Jul 18, 2025 | The Knowledge Base plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin slug setting in all ... |
| CVE-2025-7767 | MEDIUM | 5.4 | 0.2% | Jul 18, 2025 | A vulnerability, which was classified as problematic, has been found in PHPGurukul Art Gallery Management System 1.1. Af... |
| CVE-2025-7763 | MEDIUM | 4.3 | 0.4% | Jul 17, 2025 | A vulnerability, which was classified as problematic, was found in thinkgem JeeSite up to 5.12.0. Affected is the functi... |
| CVE-2025-7762 | MEDIUM | 6.5 | 3.3% | Jul 17, 2025 | A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07.26A1. This issue affects some ... |
| CVE-2025-7756 | MEDIUM | 4.3 | 0.2% | Jul 17, 2025 | A vulnerability classified as problematic has been found in code-projects E-Commerce Site 1.0. Affected is an unknown fu... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now