2025 CVE Vulnerabilities
45,254 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4643 | MEDIUM | 6.3 | 0.5% | Aug 29, 2025 | Payload uses JSON Web Tokens (JWT) for authentication. After log out JWT is not invalidated, which allows an attacker wh... |
| CVE-2025-8150 | MEDIUM | 6.4 | 0.2% | Aug 29, 2025 | The Events Addon for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Typewr... |
| CVE-2025-54777 | MEDIUM | 5.3 | 0.1% | Aug 29, 2025 | Uncaught exception issue exists in Multiple products in bizhub series. If a malformed file is imported as an S/MIME Emai... |
| CVE-2025-9441 | MEDIUM | 6.5 | 0.3% | Aug 29, 2025 | The iATS Online Forms plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order' parameter in all ve... |
| CVE-2025-9374 | MEDIUM | 4.3 | 0.1% | Aug 29, 2025 | The Ultimate Tag Warrior Importer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2025-8619 | MEDIUM | 6.4 | 0.2% | Aug 29, 2025 | The OSM Map Widget for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Map ... |
| CVE-2025-8290 | MEDIUM | 6.4 | 0.2% | Aug 29, 2025 | The List Subpages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all ver... |
| CVE-2025-8147 | MEDIUM | 4.3 | 0.2% | Aug 29, 2025 | The LWSCache plugin for WordPress is vulnerable to unauthorized modification of data due to improper authorization on th... |
| CVE-2025-53508 | HIGH | 8.6 | 1.3% | Aug 29, 2025 | Multiple products provided by iND Co.,Ltd contain an OS command injection vulnerability. If exploited, an arbitrary OS c... |
| CVE-2025-53507 | HIGH | 7.1 | 0.3% | Aug 29, 2025 | Multiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploit... |
| CVE-2025-9639 | HIGH | 8.7 | 0.5% | Aug 29, 2025 | The QbiCRMGateway developed by Ai3 has an Arbitrary File Reading vulnerability, allowing unauthenticated remote attacker... |
| CVE-2025-9619 | MEDIUM | 6.9 | 0.3% | Aug 29, 2025 | A security flaw has been discovered in E4 Sistemas Mercatus ERP 2.00.019. The affected element is an unknown function of... |
| CVE-2025-9610 | CRITICAL | 9.8 | 0.4% | Aug 29, 2025 | A vulnerability was determined in code-projects Online Event Judging System 1.0. This issue affects some unknown process... |
| CVE-2025-9609 | HIGH | 8.8 | 0.3% | Aug 29, 2025 | A vulnerability was found in Portabilis i-Educar up to 2.10. This vulnerability affects unknown code of the file /educac... |
| CVE-2025-8861 | CRITICAL | 9.8 | 0.5% | Aug 29, 2025 | TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read,... |
| CVE-2025-8858 | HIGH | 8.7 | 0.4% | Aug 29, 2025 | Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers t... |
| CVE-2025-8857 | CRITICAL | 9.8 | 0.5% | Aug 29, 2025 | Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to ... |
| CVE-2025-9608 | HIGH | 8.8 | 0.4% | Aug 29, 2025 | A vulnerability has been found in Portabilis i-Educar up to 2.10. This affects an unknown part of the file /module/Formu... |
| CVE-2025-9607 | HIGH | 8.8 | 0.4% | Aug 29, 2025 | A flaw has been found in Portabilis i-Educar up to 2.10. Affected by this issue is some unknown functionality of the fil... |
| CVE-2025-9606 | HIGH | 8.8 | 0.3% | Aug 29, 2025 | A vulnerability was detected in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionali... |
| CVE-2025-9605 | CRITICAL | 9.8 | 1.0% | Aug 29, 2025 | A security vulnerability has been detected in Tenda AC21 and AC23 16.03.08.16. Affected is the function GetParentControl... |
| CVE-2025-58333 | — | — | — | Aug 29, 2025 | Rejected reason: Not used |
| CVE-2025-58332 | — | — | — | Aug 29, 2025 | Rejected reason: Not used |
| CVE-2025-58331 | — | — | — | Aug 29, 2025 | Rejected reason: Not used |
| CVE-2025-58330 | — | — | — | Aug 29, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now