2025 CVE Vulnerabilities
45,175 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54006 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in boldthemes Bold Pa... |
| CVE-2025-53997 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in favethemes Houzez houzez allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-53996 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetSear... |
| CVE-2025-53995 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopu... |
| CVE-2025-53994 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetPopu... |
| CVE-2025-53991 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTric... |
| CVE-2025-53989 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetBloc... |
| CVE-2025-53986 | MEDIUM | 5.3 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in themeisle Hestia hestia allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-53984 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs... |
| CVE-2025-53982 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetElem... |
| CVE-2025-48295 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy El... |
| CVE-2025-48294 | MEDIUM | 4.4 | 0.2% | Jul 16, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Kerfred FG Drupal to WordPress fg-drupal-to-wp allows Server Side Re... |
| CVE-2025-48167 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in alexvtn Chatbox Manager wa-chatbox-manager allows Exploiting Incorrectly Configur... |
| CVE-2025-48166 | MEDIUM | 5.3 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in sminozzi Stop and Block bots plugin Anti bots antibots allows Accessing Functiona... |
| CVE-2025-48156 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wal... |
| CVE-2025-48155 | MEDIUM | 5.3 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all... |
| CVE-2025-48150 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugi... |
| CVE-2025-7035 | MEDIUM | 5.4 | 0.3% | Jul 16, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_c... |
| CVE-2025-5284 | MEDIUM | 6.4 | 0.3% | Jul 16, 2025 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ... |
| CVE-2025-40724 | MEDIUM | 5.1 | 0.4% | Jul 16, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to exe... |
| CVE-2025-22227 | MEDIUM | 6.1 | 0.3% | Jul 16, 2025 | In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to hap... |
| CVE-2025-27465 | MEDIUM | 4.3 | 0.6% | Jul 16, 2025 | Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it... |
| CVE-2025-6747 | MEDIUM | 6.4 | 0.2% | Jul 16, 2025 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_ma... |
| CVE-2025-5845 | MEDIUM | 6.4 | 0.2% | Jul 16, 2025 | The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter i... |
| CVE-2025-5843 | MEDIUM | 6.4 | 0.2% | Jul 16, 2025 | The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now