2025 CVE Vulnerabilities
45,254 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8062 | MEDIUM | 6.4 | 0.2% | Aug 23, 2025 | The WS Theme Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ws_weather shortc... |
| CVE-2025-7957 | MEDIUM | 6.4 | 0.2% | Aug 23, 2025 | The ShortcodeHub plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘author_link_target’ paramete... |
| CVE-2025-7842 | MEDIUM | 4.3 | 0.1% | Aug 23, 2025 | The Silencesoft RSS Reader plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2025-7841 | MEDIUM | 4.3 | 0.1% | Aug 23, 2025 | The Sertifier Certificate & Badge Maker for WordPress – Tutor LMS plugin for WordPress is vulnerable to Cross-Site Reque... |
| CVE-2025-7839 | MEDIUM | 4.3 | 0.1% | Aug 23, 2025 | The Restore Permanently delete Post or Page Data plugin for WordPress is vulnerable to Cross-Site Request Forgery in all... |
| CVE-2025-7828 | MEDIUM | 4.3 | 0.2% | Aug 23, 2025 | The WP Filter & Combine RSS Feeds plugin for WordPress is vulnerable to unauthorized modification of data due to a missi... |
| CVE-2025-7827 | MEDIUM | 4.3 | 0.2% | Aug 23, 2025 | The Ni WooCommerce Customer Product Report plugin for WordPress is vulnerable to unauthorized modification of data due t... |
| CVE-2025-7821 | MEDIUM | 5.3 | 0.2% | Aug 23, 2025 | The WC Plus plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2025-7642 | CRITICAL | 9.8 | 0.5% | Aug 23, 2025 | The Simpler Checkout plugin for WordPress is vulnerable to Authentication Bypass in versions 0.7.0 to 1.1.9. This is due... |
| CVE-2025-43766 | CRITICAL | 9.8 | 0.4% | Aug 23, 2025 | The Liferay Portal 7.4.0 through 7.3.3.131, and Liferay DXP 2024.Q4.0, 2024.Q3.1 through 2024.Q3.13, 2024.Q2.0 through 2... |
| CVE-2025-43765 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | A Stored cross-site scripting vulnerability in the Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0, 20... |
| CVE-2025-43764 | MEDIUM | 6.5 | 0.3% | Aug 23, 2025 | Self-ReDoS (Regular expression Denial of Service) exists with Role Name search field of Kaleo Designer portlet JavaScrip... |
| CVE-2025-43767 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | Open Redirect vulnerability in /c/portal/edit_info_item parameter redirect in Liferay Portal 7.4.3.86 through 7.4.3.131,... |
| CVE-2025-58043 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58042 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58041 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58040 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58039 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58038 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58037 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58036 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-58035 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
| CVE-2025-43769 | MEDIUM | 6.1 | 0.2% | Aug 23, 2025 | Stored cross-site scripting (XSS) vulnerability in Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q3.1 thr... |
| CVE-2025-43768 | HIGH | 7.7 | 0.3% | Aug 23, 2025 | Liferay Portal 7.4.0 through 7.4.3.131, and Liferay DXP 2024.Q4.0 through 2024.Q4.7, 2024.Q3.1 through 2024.Q3.13, 2024.... |
| CVE-2025-24469 | — | — | — | Aug 23, 2025 | Rejected reason: Not used |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now