2025 CVE Vulnerabilities
45,255 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48161 | HIGH | 7.6 | 0.4% | Jul 16, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YayCommerce YaySMT... |
| CVE-2025-48156 | MEDIUM | 6.5 | 0.2% | Jul 16, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Parakoos Image Wal... |
| CVE-2025-48155 | MEDIUM | 5.3 | 0.3% | Jul 16, 2025 | Missing Authorization vulnerability in enituretechnology Residential Address Detection residential-address-detection all... |
| CVE-2025-48153 | HIGH | 7.1 | 0.1% | Jul 16, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Atakan Au Import CDN-Remote Images import-cdn-remote-images allows St... |
| CVE-2025-48150 | MEDIUM | 4.3 | 0.2% | Jul 16, 2025 | Missing Authorization vulnerability in sminozzi Real Estate Property 2024 Create Your Own Fields and Search Bar WP Plugi... |
| CVE-2025-7699 | HIGH | 7.1 | 0.3% | Jul 16, 2025 | An improper access control vulnerability was found in the EZ Sync Manager of ADM, which allows authenticated users to c... |
| CVE-2025-7035 | MEDIUM | 5.4 | 0.3% | Jul 16, 2025 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mla_tag_c... |
| CVE-2025-6993 | HIGH | 8.8 | 0.4% | Jul 16, 2025 | The Ultimate WP Mail plugin for WordPress is vulnerable to Privilege Escalation due to improper authorization within the... |
| CVE-2025-5284 | MEDIUM | 6.4 | 0.3% | Jul 16, 2025 | The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for ... |
| CVE-2025-40985 | HIGH | 8.3 | 0.3% | Jul 16, 2025 | SQL injection vulnerability in SCATI Vision Web of SCATI Labs from version 4.8 to 7.2. This vulnerability allows an atta... |
| CVE-2025-40724 | MEDIUM | 5.1 | 0.4% | Jul 16, 2025 | Stored Cross-Site Scripting (XSS) vulnerability in Pharmacy POS PHP Script. This vulnerability allows an attacker to exe... |
| CVE-2025-22227 | MEDIUM | 6.1 | 0.3% | Jul 16, 2025 | In some specific scenarios with chained redirects, Reactor Netty HTTP client leaks credentials. In order for this to hap... |
| CVE-2025-7703 | LOW | 3.1 | 0.3% | Jul 16, 2025 | Authentication vulnerability in the mobile application(tech.palm.id)may lead to the risk of information leakage. |
| CVE-2025-27465 | MEDIUM | 4.3 | 0.6% | Jul 16, 2025 | Certain instructions need intercepting and emulating by Xen. In some cases Xen emulates the instruction by replaying it... |
| CVE-2025-7673 | CRITICAL | 9.8 | 0.5% | Jul 16, 2025 | A buffer overflow vulnerability in the URL parser of the zhttpd web server in Zyxel VMG8825-T50K firmware versions prior... |
| CVE-2025-7359 | HIGH | 8.2 | 0.4% | Jul 16, 2025 | The Counter live visitors for WooCommerce plugin for WordPress is vulnerable to arbitrary file deletion due to insuffici... |
| CVE-2025-6747 | MEDIUM | 6.4 | 0.2% | Jul 16, 2025 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fusion_ma... |
| CVE-2025-6043 | HIGH | 8.1 | 0.5% | Jul 16, 2025 | The Malcure Malware Scanner — #1 Toolset for WordPress Malware Removal plugin for WordPress is vulnerable to Arbitrary F... |
| CVE-2025-5845 | MEDIUM | 6.4 | 0.2% | Jul 16, 2025 | The Affiliate Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘numColumns’ parameter i... |
| CVE-2025-5843 | MEDIUM | 6.4 | 0.2% | Jul 16, 2025 | The Brandfolder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions... |
| CVE-2025-52690 | HIGH | 8.1 | 9.2% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker to execute arbitrary commands as root, potentially ... |
| CVE-2025-52689 | CRITICAL | 9.8 | 11.0% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to obtain a valid session ID with a... |
| CVE-2025-52688 | CRITICAL | 9.8 | 22.5% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker to inject commands with root privileges on the acce... |
| CVE-2025-52687 | LOW | 2.4 | 0.2% | Jul 16, 2025 | Successful exploitation of the vulnerability could allow an attacker with administrator credentials for the access point... |
| CVE-2025-2800 | MEDIUM | 6.1 | 0.3% | Jul 16, 2025 | The WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce plugin for WordPress is vulnerable ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now