2025 CVE Vulnerabilities
45,254 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-9345 | MEDIUM | 4.9 | 0.5% | Aug 28, 2025 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versio... |
| CVE-2025-8603 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widge... |
| CVE-2025-0951 | MEDIUM | 4.3 | 0.2% | Aug 28, 2025 | Multiple plugins and/or themes for WordPress by LiquidThemes are vulnerable to unauthorized access due to a missing capa... |
| CVE-2025-9352 | MEDIUM | 5.4 | 0.2% | Aug 28, 2025 | The Pronamic Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the description field in ... |
| CVE-2025-9344 | MEDIUM | 6.4 | 0.2% | Aug 28, 2025 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2025-8897 | MEDIUM | 6.1 | 0.2% | Aug 28, 2025 | The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the... |
| CVE-2025-7812 | HIGH | 8.8 | 0.2% | Aug 28, 2025 | The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery... |
| CVE-2025-57845 | — | — | — | Aug 28, 2025 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2025-34158. Reason: This candidate is a reservation d... |
| CVE-2025-36003 | MEDIUM | 5.3 | 0.3% | Aug 28, 2025 | IBM Security Verify Governance Identity Manager 10.0.2 could allow a remote attacker to obtain sensitive information whe... |
| CVE-2025-34523 | CRITICAL | 9.8 | 0.5% | Aug 27, 2025 | A heap-based buffer overflow vulnerability exists in the network-facing input handling routines of Arcserve Unified Data... |
| CVE-2025-34522 | CRITICAL | 9.8 | 0.5% | Aug 27, 2025 | A heap-based buffer overflow vulnerability exists in the input parsing logic of Arcserve Unified Data Protection (UDP). ... |
| CVE-2025-34521 | MEDIUM | 5.4 | 0.2% | Aug 27, 2025 | A reflected cross-site scripting (XSS) vulnerability exists in the web interface of the Arcserve Unified Data Protection... |
| CVE-2025-34520 | CRITICAL | 9.8 | 0.3% | Aug 27, 2025 | An authentication bypass vulnerability in Arcserve Unified Data Protection (UDP) allows unauthenticated attackers to gai... |
| CVE-2025-34163 | CRITICAL | 10 | 0.7% | Aug 27, 2025 | Dongsheng Logistics Software exposes an unauthenticated endpoint at /CommMng/Print/UploadMailFile that fails to enforce ... |
| CVE-2025-34162 | CRITICAL | 9.3 | 0.8% | Aug 27, 2025 | An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Eme... |
| CVE-2025-34160 | CRITICAL | 10 | 0.8% | Aug 27, 2025 | AnyShare contains a critical unauthenticated remote code execution vulnerability in the ServiceAgent API exposed on port... |
| CVE-2025-40779 | HIGH | 7.5 | 0.5% | Aug 27, 2025 | If a DHCPv4 client sends a request with some specific options, and Kea fails to find an appropriate subnet for the clien... |
| CVE-2025-5101 | MEDIUM | 5 | 0.1% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1... |
| CVE-2025-55618 | HIGH | 7.3 | 0.2% | Aug 27, 2025 | In Hyundai Navigation App STD5W.EUR.HMC.230516.afa908d, an attacker can inject HTML payloads in the profile name field i... |
| CVE-2025-55582 | MEDIUM | 6.6 | 0.2% | Aug 27, 2025 | D-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly ... |
| CVE-2025-4225 | HIGH | 7.5 | 0.3% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.... |
| CVE-2025-3601 | MEDIUM | 6.5 | 0.3% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions from 8.15 before 18.1.5, 18.2 before 18.2.5, and 18.... |
| CVE-2025-2246 | MEDIUM | 5.3 | 0.3% | Aug 27, 2025 | An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 1... |
| CVE-2025-58050 | CRITICAL | 9.1 | 0.7% | Aug 27, 2025 | The PCRE2 library is a set of C functions that implement regular expression pattern matching. In version 10.45, a heap-b... |
| CVE-2025-55495 | MEDIUM | 6.5 | 0.2% | Aug 27, 2025 | Tenda AC6 V15.03.06.23_multi was discovered to contain a buffer overflow via the list parameter in the fromSetIpMacBind ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now