2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-8961 | LOW | 3.3 | 0.2% | Aug 14, 2025 | A weakness has been identified in LibTIFF 4.7.0. This affects the function main of the file tiffcrop.c of the component ... |
| CVE-2025-8715 | HIGH | 8.8 | 0.4% | Aug 14, 2025 | Improper neutralization of newlines in pg_dump in PostgreSQL allows a user of the origin server to inject arbitrary code... |
| CVE-2025-8714 | HIGH | 8.8 | 0.7% | Aug 14, 2025 | Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious superuser of the origin server to inject arbitrary ... |
| CVE-2025-8713 | LOW | 3.1 | 0.2% | Aug 14, 2025 | PostgreSQL optimizer statistics allow a user to read sampled data within a view that the user cannot access. Separately... |
| CVE-2025-8960 | CRITICAL | 9.8 | 0.5% | Aug 14, 2025 | A vulnerability has been found in Campcodes Online Flight Booking Management System 1.0. Affected by this issue is some ... |
| CVE-2025-8958 | HIGH | 8.8 | 0.7% | Aug 14, 2025 | A vulnerability was identified in Tenda TX3 16.03.13.11_multi_TDE01. Affected by this vulnerability is an unknown functi... |
| CVE-2025-8957 | CRITICAL | 9.8 | 0.4% | Aug 14, 2025 | A vulnerability was determined in Campcodes Online Flight Booking Management System 1.0. Affected is an unknown function... |
| CVE-2025-54707 | CRITICAL | 9.3 | 0.3% | Aug 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 MDTF wp... |
| CVE-2025-54706 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Noor Alam Magical ... |
| CVE-2025-54705 | MEDIUM | 4.3 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in magepeopleteam WpEvently mage-eventpress allows Exploiting Incorrectly Configured... |
| CVE-2025-54704 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in hashthemes Easy El... |
| CVE-2025-54703 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in princeahmed Integrate Google Drive integrate-google-drive allows Cros... |
| CVE-2025-54702 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.T... |
| CVE-2025-54701 | CRITICAL | 9.8 | 0.4% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54700 | CRITICAL | 9.8 | 0.4% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54699 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in masteriyo Masteriy... |
| CVE-2025-54698 | MEDIUM | 5.4 | 0.2% | Aug 14, 2025 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in RadiusTheme Classified Li... |
| CVE-2025-54697 | HIGH | 7.2 | 0.4% | Aug 14, 2025 | Incorrect Privilege Assignment vulnerability in StellarWP Kadence WooCommerce Email Designer kadence-woocommerce-email-d... |
| CVE-2025-54696 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFunnels WPFunnel... |
| CVE-2025-54695 | MEDIUM | 5.4 | 0.2% | Aug 14, 2025 | Missing Authorization vulnerability in DevItems HT Mega ht-mega-for-elementor allows Exploiting Incorrectly Configured A... |
| CVE-2025-54694 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bPlugins Button Block button-block allows Cross Site Request Forgery.... |
| CVE-2025-54693 | CRITICAL | 9 | 0.3% | Aug 14, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in epiphyt Form Block form-block allows Upload a Web Shell... |
| CVE-2025-54692 | HIGH | 7.5 | 0.3% | Aug 14, 2025 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing ... |
| CVE-2025-54691 | MEDIUM | 5.3 | 0.3% | Aug 14, 2025 | Authorization Bypass Through User-Controlled Key vulnerability in Stylemix Motors motors-car-dealership-classified-listi... |
| CVE-2025-54690 | HIGH | 8.1 | 0.4% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now