2025 CVE Vulnerabilities
45,181 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-7066 | MEDIUM | 6.1 | 0.3% | Jul 4, 2025 | Jirafeau normally prevents browser preview for text files due to the possibility that for example SVG and HTML documents... |
| CVE-2025-6740 | MEDIUM | 6.1 | 0.3% | Jul 4, 2025 | The Contact Form 7 Database Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tmpD’ param... |
| CVE-2025-6056 | MEDIUM | 6.9 | 0.3% | Jul 4, 2025 | Timing difference in password reset in Ergon Informatik AG's Airlock IAM 7.7.9, 8.0.8, 8.1.7, 8.2.4 and 8.3.1 allows una... |
| CVE-2025-50039 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in vgwort VG WORT METIS vgw-metis allows Exploiting Incorrectly Configured Access Co... |
| CVE-2025-50032 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in Paytiko - Payment Orchestration Platform Paytiko for WooCommerce paytiko allows E... |
| CVE-2025-49431 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in Gnuget MF Plus WPML mf-plus-wpml allows Exploiting Incorrectly Configured Access ... |
| CVE-2025-49303 | MEDIUM | 6.8 | 0.4% | Jul 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend A... |
| CVE-2025-48231 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking... |
| CVE-2025-47634 | MEDIUM | 6.5 | 0.3% | Jul 4, 2025 | Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store wc-pickup-store allows Exploiting Incorrectly Conf... |
| CVE-2025-47565 | MEDIUM | 6.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-28976 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dsrodzin Email Add... |
| CVE-2025-38174 | MEDIUM | 5.5 | 0.2% | Jul 4, 2025 | In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Do not double dequeue a configuration ... |
| CVE-2025-5351 | MEDIUM | 6.5 | 0.5% | Jul 4, 2025 | A flaw was found in the key export functionality of libssh. The issue occurs in the internal function responsible for co... |
| CVE-2025-53569 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Trust Payments Trust Payments Gateway for WooCommerce (JavaScript Lib... |
| CVE-2025-53568 | MEDIUM | 4.3 | 0.1% | Jul 4, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tony Zeoli Radio Station radio-station allows Cross Site Request Forg... |
| CVE-2025-53566 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osama.esh WP Visit... |
| CVE-2025-30983 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus Card flip... |
| CVE-2025-30943 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Aakif Kadiwala Pos... |
| CVE-2025-30929 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in amazewp fluXtore fluxtore allows Exploiting Incorrectly Configured Access Control... |
| CVE-2025-29012 | MEDIUM | 5.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorre... |
| CVE-2025-29007 | MEDIUM | 4.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in LMSACE LMSACE Connect lmsace-connect allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-29001 | MEDIUM | 4.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in ZoomIt WooCommerce Shop Page Builder allows Exploiting Incorrectly Configured Acc... |
| CVE-2025-28971 | MEDIUM | 5.9 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CWD Web Designer E... |
| CVE-2025-28963 | MEDIUM | 5.4 | 0.2% | Jul 4, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Server Side Req... |
| CVE-2025-28957 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OwnerRez OwnerRez ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now