2025 CVE Vulnerabilities
45,254 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48100 | CRITICAL | 9.1 | 0.3% | Aug 28, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in extremeidea bidorbuy Store Integrator bidorbu... |
| CVE-2025-9376 | MEDIUM | 6.5 | 0.3% | Aug 28, 2025 | The Block Bad Bots and Stop Bad Bots Crawlers and Spiders and Anti Spam Protection plugin for WordPress is vulnerable to... |
| CVE-2025-39496 | CRITICAL | 9.3 | 0.3% | Aug 28, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW WooBeWoo Produ... |
| CVE-2025-55175 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Reflected XSS via sLangEdit parameter in admin's panel functionality. A malicious attacker can... |
| CVE-2025-54544 | MEDIUM | 4.8 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Stored XSS via aDirFilesDescriptions parameter in files editor functionality. Malicious attack... |
| CVE-2025-54543 | MEDIUM | 4.8 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Stored XSS via sDescriptionMeta parameter in page editor SEO functionality. Malicious attacker... |
| CVE-2025-54542 | MEDIUM | 5.5 | 0.1% | Aug 28, 2025 | QuickCMS sends password and login via GET Request. This allows a local attacker with access to the victim's browser hist... |
| CVE-2025-54541 | MEDIUM | 4.3 | 0.1% | Aug 28, 2025 | QuickCMS is vulnerable to Cross-Site Request Forgery in page deletion functionality. Malicious attacker can craft specia... |
| CVE-2025-54540 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | QuickCMS is vulnerable to Reflected XSS via sSort parameter in admin's panel functionality. A malicious attacker can cra... |
| CVE-2025-48963 | HIGH | 7.3 | 0.1% | Aug 28, 2025 | Local privilege escalation due to improper soft link handling. The following products are affected: Acronis Cyber Protec... |
| CVE-2025-58081 | HIGH | 8.7 | 0.4% | Aug 28, 2025 | Use of hard-coded password issue/vulnerability in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allo... |
| CVE-2025-58072 | HIGH | 8.7 | 0.6% | Aug 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear... |
| CVE-2025-54819 | HIGH | 7.1 | 0.4% | Aug 28, 2025 | Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and ear... |
| CVE-2025-54762 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb... |
| CVE-2025-53970 | CRITICAL | 9.8 | 0.5% | Aug 28, 2025 | SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier) allows a remote unauthenticated attacker to upload arb... |
| CVE-2025-53396 | HIGH | 7.3 | 0.1% | Aug 28, 2025 | Incorrect permission assignment for critical resource issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.... |
| CVE-2025-52460 | MEDIUM | 6.9 | 0.3% | Aug 28, 2025 | Files or directories accessible to external parties issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a... |
| CVE-2025-46409 | HIGH | 8.7 | 0.2% | Aug 28, 2025 | Inadequate encryption strength issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If thi... |
| CVE-2025-58322 | HIGH | 7.8 | 0.1% | Aug 28, 2025 | NAVER MYBOX Explorer for Windows before 3.0.8.133 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM ... |
| CVE-2025-8073 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-6255 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Dynamic AJAX Product Filters for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t... |
| CVE-2025-7956 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | The Ajax Search Lite plugin for WordPress is vulnerable to Basic Information Exposure due to missing authorization in it... |
| CVE-2025-7955 | CRITICAL | 9.8 | 0.7% | Aug 28, 2025 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation wi... |
| CVE-2025-8977 | MEDIUM | 6.5 | 0.3% | Aug 28, 2025 | The Simple Download Monitor plugin for WordPress is vulnerable to time-based SQL Injection via the order parameter in al... |
| CVE-2025-9346 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via settings in all versions up t... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now