2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48149 | HIGH | 8.1 | 0.5% | Aug 20, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48148 | CRITICAL | 10 | 14.9% | Aug 20, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in StoreKeeper B.V. StoreKeeper for WooCommerce storekeepe... |
| CVE-2025-48142 | HIGH | 8.8 | 0.3% | Aug 20, 2025 | Incorrect Privilege Assignment vulnerability in Saad Iqbal Bookify bookify allows Privilege Escalation.This issue affect... |
| CVE-2025-47650 | MEDIUM | 6.5 | 0.4% | Aug 20, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Infility Infility Global... |
| CVE-2025-30975 | HIGH | 7.5 | 0.3% | Aug 20, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in SaifuMak Add Custom Codes add-custom-codes al... |
| CVE-2025-28977 | MEDIUM | 6.1 | 0.2% | Aug 20, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress WP Pipes... |
| CVE-2025-9202 | MEDIUM | 4.3 | 0.2% | Aug 20, 2025 | The ColorMag theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on... |
| CVE-2025-8618 | MEDIUM | 6.4 | 0.2% | Aug 20, 2025 | The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugi... |
| CVE-2025-55706 | MEDIUM | 5.1 | 0.2% | Aug 20, 2025 | URL redirection to untrusted site ('Open Redirect') issue exists in Movable Type. If this vulnerability is exploited, a... |
| CVE-2025-54551 | MEDIUM | 5.3 | 0.2% | Aug 20, 2025 | Synapse Mobility 8.0, 8.0.1, 8.0.2, 8.1, and 8.1.1 contain a privilege escalation vulnerability through external control... |
| CVE-2025-53522 | MEDIUM | 6.9 | 0.2% | Aug 20, 2025 | Movable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be ... |
| CVE-2025-57791 | MEDIUM | 6.5 | 20.7% | Aug 20, 2025 | A security vulnerability has been identified that allows remote attackers to inject or manipulate command-line arguments... |
| CVE-2025-57790 | HIGH | 8.8 | 16.1% | Aug 20, 2025 | A security vulnerability has been identified that allows remote attackers to perform unauthorized file system access thr... |
| CVE-2025-57789 | MEDIUM | 5.4 | 1.1% | Aug 20, 2025 | During the brief window between installation and the first administrator login, remote attackers may exploit the default... |
| CVE-2025-57788 | MEDIUM | 6.5 | 2.7% | Aug 20, 2025 | A vulnerability in a known login mechanism allows unauthenticated attackers to execute API calls without requiring user ... |
| CVE-2025-57748 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-57747 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-57746 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-57745 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-57744 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-57743 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-57742 | — | — | — | Aug 20, 2025 | Rejected reason: Not used |
| CVE-2025-8289 | HIGH | 7.5 | 0.4% | Aug 20, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and... |
| CVE-2025-8145 | HIGH | 8.8 | 0.5% | Aug 20, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and... |
| CVE-2025-8141 | HIGH | 8.8 | 0.6% | Aug 20, 2025 | The Redirection for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient fil... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now