2025 CVE Vulnerabilities
45,179 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7672 | MEDIUM | 4.3 | 0.2% | Jul 15, 2025 | The improper default setting in JiranSoft CrossEditor4 on Windows, Linux, Unix (API modules) potentaily allows Stored XS... |
| CVE-2025-7367 | MEDIUM | 6.4 | 0.2% | Jul 15, 2025 | The Strong Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Testimonial Custom Fie... |
| CVE-2025-53891 | MEDIUM | 4.3 | 0.3% | Jul 15, 2025 | The timelineofficial/Time-Line- repository contains the source code for the TIME LINE website. A vulnerability was found... |
| CVE-2025-53889 | MEDIUM | 6.5 | 0.4% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.12.0 and prior to... |
| CVE-2025-53887 | MEDIUM | 5.3 | 0.5% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53886 | MEDIUM | 4.5 | 0.4% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53885 | MEDIUM | 4.2 | 0.2% | Jul 15, 2025 | Directus is a real-time API and App dashboard for managing SQL database content. Starting in version 9.0.0 and prior to ... |
| CVE-2025-53839 | MEDIUM | 4 | 0.2% | Jul 15, 2025 | DRACOON is a file sharing service, and the DRACOON Branding Service allows customers to customize their DRACOON interfac... |
| CVE-2025-53834 | MEDIUM | 6.3 | 0.2% | Jul 14, 2025 | Caido is a web security auditing toolkit. A reflected cross-site scripting (XSS) vulnerability was discovered in Caido’s... |
| CVE-2025-53824 | MEDIUM | 5.4 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-53822 | MEDIUM | 6.1 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-53821 | MEDIUM | 6.1 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Open Redirec... |
| CVE-2025-53820 | MEDIUM | 6.1 | 0.2% | Jul 14, 2025 | WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cro... |
| CVE-2025-53640 | MEDIUM | 6.5 | 0.6% | Jul 14, 2025 | Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Startin... |
| CVE-2025-52363 | MEDIUM | 6.8 | 0.2% | Jul 14, 2025 | Tenda CP3 Pro Firmware V22.5.4.93 contains a hardcoded root password hash in the /etc/passwd file and /etc/passwd-. An a... |
| CVE-2025-7625 | MEDIUM | 4.3 | 0.5% | Jul 14, 2025 | A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b9... |
| CVE-2025-51660 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Products.php. |
| CVE-2025-51659 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Products.php. |
| CVE-2025-51658 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_InquiryView.php. |
| CVE-2025-51657 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the lgid parameter at SEMCMS_Link.php. |
| CVE-2025-51656 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the ID parameter at SEMCMS_Link.php. |
| CVE-2025-51655 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Quanxian.php. |
| CVE-2025-51654 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Infocategories.php. |
| CVE-2025-51653 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_ct.php. |
| CVE-2025-51652 | MEDIUM | 5.4 | 0.3% | Jul 14, 2025 | SemCms v5.0 was discovered to contain a SQL injection vulnerability via the pid parameter at SEMCMS_Categories.php. |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now