2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-38504 | MEDIUM | 5.5 | 0.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: io_uring/zcrx: fix pp destruction warnings With mu... |
| CVE-2025-38503 | MEDIUM | 5.5 | 0.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix assertion when building free space tree ... |
| CVE-2025-38502 | HIGH | 7.1 | 0.2% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial... |
| CVE-2025-8719 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Translate This gTranslate Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘base_... |
| CVE-2025-8464 | MEDIUM | 5.3 | 0.7% | Aug 16, 2025 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in a... |
| CVE-2025-7499 | MEDIUM | 5.3 | 0.3% | Aug 16, 2025 | The BetterDocs – Advanced AI-Driven Documentation, FAQ & Knowledge Base Tool for Elementor & Gutenberg with Encyclopedia... |
| CVE-2025-8898 | CRITICAL | 9.8 | 0.4% | Aug 16, 2025 | The Taxi Booking Manager for Woocommerce | E-cab plugin for WordPress is vulnerable to privilege escalation via account ... |
| CVE-2025-8896 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is v... |
| CVE-2025-8089 | MEDIUM | 5.4 | 0.2% | Aug 16, 2025 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ... |
| CVE-2025-8113 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting i... |
| CVE-2025-38501 | HIGH | 7.5 | 2.1% | Aug 16, 2025 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: limit repeated connections from clients with... |
| CVE-2025-8293 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Intl DateTime Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘date’ parameter in... |
| CVE-2025-7686 | MEDIUM | 6.1 | 0.1% | Aug 16, 2025 | The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and includ... |
| CVE-2025-7684 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to,... |
| CVE-2025-7683 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including... |
| CVE-2025-7668 | MEDIUM | 6.1 | 0.2% | Aug 16, 2025 | The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and... |
| CVE-2025-7664 | HIGH | 7.5 | 0.5% | Aug 16, 2025 | The AL Pack plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the check_act... |
| CVE-2025-7651 | MEDIUM | 6.4 | 0.3% | Aug 16, 2025 | The Earnware Connect plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ew_hasrole' sho... |
| CVE-2025-7649 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Surbma | Recent Comments Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin'... |
| CVE-2025-7441 | CRITICAL | 9.8 | 37.3% | Aug 16, 2025 | The StoryChief plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.0.42... |
| CVE-2025-7440 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $item['button_link']... |
| CVE-2025-7439 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | Anber Elementor Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the $anber_item['button_link... |
| CVE-2025-6221 | MEDIUM | 6.4 | 0.2% | Aug 16, 2025 | The Embed Bokun plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ parameter in all versi... |
| CVE-2025-6080 | HIGH | 8.8 | 0.3% | Aug 16, 2025 | The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to unauthorized admin account creation in... |
| CVE-2025-6079 | HIGH | 8.8 | 0.5% | Aug 16, 2025 | The School Management System for Wordpress plugin for WordPress is vulnerable to arbitrary file uploads due to missing f... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now