2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-4523 | MEDIUM | 6.5 | 0.3% | Aug 1, 2025 | The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to unauthorized acc... |
| CVE-2025-8434 | HIGH | 7.3 | 0.4% | Aug 1, 2025 | A vulnerability was found in code-projects Online Movie Streaming 1.0. It has been classified as critical. Affected is a... |
| CVE-2025-8433 | MEDIUM | 5.4 | 0.4% | Aug 1, 2025 | A vulnerability was found in code-projects Document Management System 1.0 and classified as critical. This issue affects... |
| CVE-2025-5947 | CRITICAL | 9.8 | 5.7% | Aug 1, 2025 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via authentication bypass in all ... |
| CVE-2025-54847 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54846 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54845 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54844 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54843 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54842 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54841 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54840 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54839 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-54657 | — | — | — | Aug 1, 2025 | Rejected reason: Not used |
| CVE-2025-53399 | MEDIUM | 6.9 | 5.0% | Aug 1, 2025 | In Sipwise rtpengine before 13.4.1.1, an origin-validation error in the endpoint-learning logic of the media-relay core ... |
| CVE-2025-5954 | CRITICAL | 9.8 | 0.4% | Aug 1, 2025 | The Service Finder SMS System plugin for WordPress is vulnerable to privilege escalation via account takeover in all ver... |
| CVE-2025-8431 | CRITICAL | 9.8 | 0.5% | Aug 1, 2025 | A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affe... |
| CVE-2025-48073 | MEDIUM | 6.2 | 0.2% | Jul 31, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-48072 | CRITICAL | 9.1 | 0.5% | Jul 31, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-48071 | HIGH | 7.8 | 0.3% | Jul 31, 2025 | OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the ... |
| CVE-2025-45768 | HIGH | 7 | 0.2% | Jul 31, 2025 | pyjwt v2.10.1 was discovered to contain weak encryption. NOTE: this is disputed by the Supplier because the key length i... |
| CVE-2025-23289 | MEDIUM | 5.5 | 0.1% | Jul 31, 2025 | NVIDIA Omniverse Launcher for Windows and Linux contains a vulnerability in the launcher logs, where a user could cause ... |
| CVE-2025-8286 | CRITICAL | 9.3 | 1.2% | Jul 31, 2025 | The affected products expose an unauthenticated Telnet-based command line interface that could allow an attacker to modi... |
| CVE-2025-50572 | HIGH | 8.8 | 0.4% | Jul 31, 2025 | Archer 6.11.00204.10014 allows attackers to execute arbitrary code via crafted system inputs that would be exported into... |
| CVE-2025-45770 | HIGH | 7 | 0.1% | Jul 31, 2025 | jwt v5.4.3 was discovered to contain weak encryption. NOTE: this issue has been disputed on the basis that key lengths a... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now