2025 CVE Vulnerabilities
45,251 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-58601 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in RadiusTheme Classified Listing classified-listing allows Exploiting Incorrectly C... |
| CVE-2025-58600 | MEDIUM | 5.3 | 0.3% | Sep 3, 2025 | Missing Authorization vulnerability in Cozmoslabs Paid Member Subscriptions paid-member-subscriptions allows Exploiting ... |
| CVE-2025-58599 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in tychesoftwares Order Delivery Date for WooCommerce order-delivery-date-for-woocom... |
| CVE-2025-58598 | MEDIUM | 6.6 | 0.2% | Sep 3, 2025 | Insertion of Sensitive Information Into Debugging Code vulnerability in Klarna Klarna Order Management for WooCommerce k... |
| CVE-2025-58597 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Tomdever wpForo Forum wpforo allows Exploiting Incorre... |
| CVE-2025-58596 | MEDIUM | 5.9 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in properfraction Mai... |
| CVE-2025-58594 | MEDIUM | 4.3 | 0.2% | Sep 3, 2025 | Missing Authorization vulnerability in themefusecom Brizy brizy allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-58593 | MEDIUM | 6.5 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Themeisle Orbit Fo... |
| CVE-2025-58460 | MEDIUM | 4.2 | 0.2% | Sep 3, 2025 | A missing permission check in Jenkins OpenTelemetry Plugin 3.1543.v8446b_92b_cd64 and earlier allows attackers with Over... |
| CVE-2025-58459 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | Jenkins global-build-stats Plugin 322.v22f4db_18e2dd and earlier does not perform permission checks in its REST API endp... |
| CVE-2025-58458 | MEDIUM | 4.3 | 0.3% | Sep 3, 2025 | In Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ b... |
| CVE-2025-57151 | HIGH | 8.8 | 0.6% | Sep 3, 2025 | phpgurukul Complaint Management System 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/userprofile.php via the ... |
| CVE-2025-57150 | HIGH | 7.2 | 0.6% | Sep 3, 2025 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to Cross Site Scripting (XSS) in admin/subcategory.php v... |
| CVE-2025-57149 | MEDIUM | 6.5 | 0.4% | Sep 3, 2025 | phpgurukul Complaint Management System 2.0 is vulnerable to SQL Injection in /complaint-details.php via the cid paramete... |
| CVE-2025-57148 | CRITICAL | 9.1 | 0.4% | Sep 3, 2025 | phpgurukul Online Shopping Portal 2.0 is vulnerable to Arbitrary File Upload in /admin/insert-product.php, due to the la... |
| CVE-2025-57147 | HIGH | 7.5 | 0.5% | Sep 3, 2025 | A SQL Injection vulnerability was found in phpgurukul Complaint Management System 2.0. The vulnerability is due to lack ... |
| CVE-2025-57146 | HIGH | 8.1 | 0.4% | Sep 3, 2025 | phpgurukul Complaint Management System in PHP 2.0 is vulnerable to SQL Injection in user/reset-password.php via the mobi... |
| CVE-2025-57052 | CRITICAL | 9.8 | 0.7% | Sep 3, 2025 | cJSON 1.5.0 through 1.7.18 allows out-of-bounds access via the decode_array_index_from_pointer function in cJSON_Utils.c... |
| CVE-2025-56608 | MEDIUM | 4.2 | 0.3% | Sep 3, 2025 | The SourceCodester Android application "Corona Virus Tracker App India" 1.0 uses MD5 for digest authentication in `OkHtt... |
| CVE-2025-9822 | MEDIUM | 5.5 | 0.2% | Sep 3, 2025 | SummaryA user with administrator rights can change the configuration of the mautic application and extract secrets that ... |
| CVE-2025-47421 | HIGH | 8.6 | 0.3% | Sep 3, 2025 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in CRESTRON TOUCHSCREEN... |
| CVE-2025-2416 | HIGH | 8.6 | 0.3% | Sep 3, 2025 | Improper Restriction of Excessive Authentication Attempts vulnerability in Akinsoft LimonDesk allows Authentication Bypa... |
| CVE-2025-26210 | HIGH | 8.8 | 0.5% | Sep 3, 2025 | DeepSeek R1 through V3.1 allows XSS, as demonstrated by JavaScript execution in the context of the run-html-chat.deepsee... |
| CVE-2025-0878 | MEDIUM | 4.7 | 0.2% | Sep 3, 2025 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Akinsoft Li... |
| CVE-2025-9901 | MEDIUM | 5.9 | 0.4% | Sep 3, 2025 | A flaw was found in libsoup’s caching mechanism, SoupCache, where the HTTP Vary header is ignored when evaluating cached... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now