2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-54689 | HIGH | 8.1 | 0.4% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-54688 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetEngi... |
| CVE-2025-54687 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock JetTabs... |
| CVE-2025-54686 | CRITICAL | 9.8 | 0.4% | Aug 14, 2025 | Deserialization of Untrusted Data vulnerability in scriptsbundle Exertio exertio allows Object Injection.This issue affe... |
| CVE-2025-54685 | MEDIUM | 6.5 | 0.3% | Aug 14, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in Brainstorm Force SureDash suredash allows Retrieve Em... |
| CVE-2025-54684 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CRM Perks Integrat... |
| CVE-2025-54683 | MEDIUM | 5.9 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Astoundify WP Moda... |
| CVE-2025-54682 | MEDIUM | 5.4 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-fo... |
| CVE-2025-54681 | MEDIUM | 4.7 | 0.2% | Aug 14, 2025 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in CRM Perks Connector for Gravity Forms and Google Sh... |
| CVE-2025-54680 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sparklewpthemes Bl... |
| CVE-2025-54679 | HIGH | 7.5 | 0.4% | Aug 14, 2025 | Missing Authorization vulnerability in vertim Neon Channel Product Customizer Free neon-channel-product-customizer-free ... |
| CVE-2025-54678 | CRITICAL | 9.3 | 0.3% | Aug 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hassantafreshi Eas... |
| CVE-2025-54676 | MEDIUM | 5.4 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booki... |
| CVE-2025-54675 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH WooCommerce Popup yith-woocommerce-popup allows Cross S... |
| CVE-2025-54674 | MEDIUM | 5.4 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-f... |
| CVE-2025-54673 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Ays Pro Chartify chart-builder allows Cross Site Request Forgery.This... |
| CVE-2025-54672 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Jordy Meow Photo Engine wplr-sync allows Cross Site Request Forgery.T... |
| CVE-2025-54671 | MEDIUM | 4.3 | 0.1% | Aug 14, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in bobbingwide oik oik allows Cross Site Request Forgery.This issue affe... |
| CVE-2025-54669 | CRITICAL | 9.3 | 0.3% | Aug 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RomanCode MapSVG m... |
| CVE-2025-54668 | MEDIUM | 6.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saad Iqbal myCred ... |
| CVE-2025-54667 | MEDIUM | 5.3 | 0.2% | Aug 14, 2025 | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Saad Iqbal myCred mycred allows Leveraging Time-of-Ch... |
| CVE-2025-52823 | HIGH | 8.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ovatheme Cube Port... |
| CVE-2025-52820 | HIGH | 8.5 | 0.2% | Aug 14, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in infosoftplugin Woo... |
| CVE-2025-52806 | HIGH | 7.5 | 0.5% | Aug 14, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-52801 | HIGH | 7.3 | 0.3% | Aug 14, 2025 | Missing Authorization vulnerability in VonStroheim TheBooking thebooking allows Accessing Functionality Not Properly Con... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now