2025 CVE Vulnerabilities
45,262 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49418 | HIGH | 7.2 | 0.2% | Jul 4, 2025 | Server-Side Request Forgery (SSRF) vulnerability in TeconceTheme Allmart allmart-core allows Server Side Request Forgery... |
| CVE-2025-49417 | CRITICAL | 9.8 | 0.4% | Jul 4, 2025 | Deserialization of Untrusted Data vulnerability in BestWpDeveloper WooCommerce Product Multi-Action Woo-product-multiact... |
| CVE-2025-49414 | CRITICAL | 10 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Fastw3b LLC FW Gallery fw-gallery allows Using Maliciou... |
| CVE-2025-49303 | MEDIUM | 6.8 | 0.4% | Jul 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Shabti Kaplan Frontend A... |
| CVE-2025-49302 | CRITICAL | 10 | 0.4% | Jul 4, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy Stripe easy-stripe allows... |
| CVE-2025-49274 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in awordpresslife Neo... |
| CVE-2025-49247 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Team Show... |
| CVE-2025-49245 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cmoreira Testimoni... |
| CVE-2025-49070 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48231 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Booking... |
| CVE-2025-47634 | MEDIUM | 6.5 | 0.3% | Jul 4, 2025 | Missing Authorization vulnerability in Keylor Mendoza WC Pickup Store wc-pickup-store allows Exploiting Incorrectly Conf... |
| CVE-2025-47627 | HIGH | 7.5 | 0.4% | Jul 4, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47565 | MEDIUM | 6.3 | 0.2% | Jul 4, 2025 | Missing Authorization vulnerability in ashanjay EventON eventon allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2025-47479 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Weak Authentication vulnerability in AresIT WP Compress wp-compress-image-optimizer allows Authentication Abuse.This iss... |
| CVE-2025-39487 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ValvePress Rankie ... |
| CVE-2025-32311 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuanticaLabs Press... |
| CVE-2025-32297 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simpl... |
| CVE-2025-31037 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in favethemes Homey h... |
| CVE-2025-30933 | CRITICAL | 10 | 0.3% | Jul 4, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in LiquidThemes LogisticsHub logistics-hub allows Upload a... |
| CVE-2025-28983 | CRITICAL | 9.8 | 0.3% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickandPledge Cli... |
| CVE-2025-28980 | HIGH | 7.7 | 0.4% | Jul 4, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in machouinard Aviation Wea... |
| CVE-2025-28978 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Hung Trang Si SB B... |
| CVE-2025-28976 | MEDIUM | 6.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dsrodzin Email Add... |
| CVE-2025-28968 | HIGH | 7.1 | 0.2% | Jul 4, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vladimir Prelovac ... |
| CVE-2025-24780 | HIGH | 8.5 | 0.2% | Jul 4, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcar... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now