2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-57734 | MEDIUM | 6.5 | 0.7% | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 aWS credentials were exposed in Docker script files |
| CVE-2025-57733 | LOW | 3.8 | 0.3% | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 sMTP injection was possible allowing modification of email content |
| CVE-2025-57732 | MEDIUM | 6.3 | 0.1% | Aug 20, 2025 | In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory ownership |
| CVE-2025-57731 | MEDIUM | 5.4 | 0.3% | Aug 20, 2025 | In JetBrains YouTrack before 2025.2.92387 stored XSS was possible via Mermaid diagram content |
| CVE-2025-57730 | MEDIUM | 4.6 | 0.4% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 hTML injection was possible via Remote Development feature |
| CVE-2025-57729 | HIGH | 7.3 | 0.1% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 unexpected plugin startup was possible due to automatic LSP server start |
| CVE-2025-57728 | MEDIUM | 6.5 | 0.2% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 improper access control allowed Code With Me guest to discover hidden files |
| CVE-2025-57727 | HIGH | 7.5 | 0.2% | Aug 20, 2025 | In JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote reference |
| CVE-2025-9229 | MEDIUM | 5.3 | 0.3% | Aug 20, 2025 | Information disclosure vulnerability in error handling in MiR software prior to version 3.0.0 allows unauthenticated att... |
| CVE-2025-9228 | MEDIUM | 4.3 | 0.2% | Aug 20, 2025 | MiR software versions prior to version 3.0.0 have insufficient authorization controls when creating text notes, allowin... |
| CVE-2025-5261 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Ex... |
| CVE-2025-5260 | HIGH | 8.6 | 0.3% | Aug 20, 2025 | Server-Side Request Forgery (SSRF) vulnerability in Pik Online Yazılım Çözümleri A.Ş. Pik Online allows Server Side Requ... |
| CVE-2025-9225 | MEDIUM | 5.5 | 0.2% | Aug 20, 2025 | Stored cross-site scripting (XSS) in the web interface of MiR software versions prior to 3.0.0 on MiR Robots and MiR Fle... |
| CVE-2025-55715 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Themeisle Otter - Gutenberg Block otter-blocks allows... |
| CVE-2025-54750 | HIGH | 7.5 | 0.5% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54735 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in Imran Tauqeer CubeWP cubewp-framework allows Privilege Escalation.This i... |
| CVE-2025-54726 | CRITICAL | 9.3 | 1.4% | Aug 20, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Miguel Useche JS A... |
| CVE-2025-54713 | CRITICAL | 9.8 | 0.5% | Aug 20, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in magepeopleteam Taxi Booking Manager for WooCom... |
| CVE-2025-54677 | HIGH | 7.2 | 0.4% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in vcita Online Booking & Scheduling Calendar for WordPres... |
| CVE-2025-54670 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bobbingwide oik oi... |
| CVE-2025-54056 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Respo... |
| CVE-2025-54055 | HIGH | 7.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in skygroup Druco dru... |
| CVE-2025-54053 | MEDIUM | 6.6 | 0.3% | Aug 20, 2025 | Deserialization of Untrusted Data vulnerability in Adrian Tobey Groundhogg groundhogg allows Object Injection.This issue... |
| CVE-2025-54052 | HIGH | 7.5 | 0.2% | Aug 20, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl... |
| CVE-2025-54049 | CRITICAL | 9.9 | 0.4% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalati... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now