2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-28982 | CRITICAL | 9.8 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ThimPress WP Pipes... |
| CVE-2025-28965 | HIGH | 8.6 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Accessing Functionality Not ... |
| CVE-2025-28961 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in Md Yeasin Ul Haider URL Shortener exact-links allows Object Injection... |
| CVE-2025-28959 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Md Yeasin Ul Haide... |
| CVE-2025-28955 | HIGH | 7.5 | 0.5% | Jul 16, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in FWDesign Easy Video Play... |
| CVE-2025-24779 | HIGH | 8.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in NooTheme Yogi yogi allows Object Injection.This issue affects Yogi: f... |
| CVE-2025-24777 | HIGH | 8.8 | 0.5% | Jul 16, 2025 | Deserialization of Untrusted Data vulnerability in awethemes Hillter allows Object Injection. This issue affects Hillter... |
| CVE-2025-24759 | CRITICAL | 9.3 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CMSJunkie - WordPr... |
| CVE-2025-54051 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins LightBox ... |
| CVE-2025-54050 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CyberChimps Respon... |
| CVE-2025-54047 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in QuanticaLabs Cost Calculator ql-cost-calculator allows Exploiting Incorrectly Con... |
| CVE-2025-54043 | HIGH | 7.6 | 0.3% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce SMTP f... |
| CVE-2025-54042 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Xfinitysoft WP Post Hide wp-post-hide allows Cross Site Request Forge... |
| CVE-2025-54041 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WP Swings Wallet System for WooCommerce wallet-system-for-woocommerce... |
| CVE-2025-54039 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Toast Plugins Animator scroll-triggered-animations allows Cross Site ... |
| CVE-2025-54038 | MEDIUM | 5.4 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in jetmonsters Restaurant Menu by MotoPress mp-restaurant-menu allows Cr... |
| CVE-2025-54037 | MEDIUM | 5.4 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in blazethemes News Kit Elementor Addons news-kit-elementor-addons allows Exploiting... |
| CVE-2025-54036 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Webba Appointment Booking Webba Booking webba-booking-lite allows Cro... |
| CVE-2025-54035 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Software Newsletters newsletters-lite allows Cross Site Req... |
| CVE-2025-54033 | MEDIUM | 6.5 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in BlocksWP Theme Builder For Elementor theme-builder-for-elementor allo... |
| CVE-2025-54030 | MEDIUM | 4.3 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in WesternDeal WooCommerce Google Sheet Connector wc-gsheetconnector all... |
| CVE-2025-54026 | HIGH | 8.5 | 0.3% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in QuanticaLabs GymBa... |
| CVE-2025-54024 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Greg Winiarski WPA... |
| CVE-2025-54023 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Delicious WP De... |
| CVE-2025-54022 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Elliot Sowersby / RelyWP Coupon Affiliates woo-coupon-usage allows Cr... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now