2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49330 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in CRM Perks Integration for Contact Form 7 and Zoho CRM, Bigin cf7-zoho... |
| CVE-2025-49316 | HIGH | 7.1 | 0.3% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Saleswonder Team: ... |
| CVE-2025-49312 | HIGH | 7.1 | 0.3% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CodeRevolution Ech... |
| CVE-2025-49266 | HIGH | 7.1 | 0.3% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rustaurius Ultimat... |
| CVE-2025-49261 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49260 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49259 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49258 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49257 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49256 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49255 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49254 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49253 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49252 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49251 | HIGH | 8.1 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49234 | MEDIUM | 6.5 | 0.3% | Jun 17, 2025 | Missing Authorization vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator allows Exploit... |
| CVE-2025-49180 | HIGH | 7.8 | 0.3% | Jun 17, 2025 | A flaw was found in the RandR extension, where the RRChangeProviderProperty function does not properly validate input. T... |
| CVE-2025-49179 | HIGH | 7.3 | 0.3% | Jun 17, 2025 | A flaw was found in the X Record extension. The RecordSanityCheckRegisterClients function does not check for an integer ... |
| CVE-2025-49178 | MEDIUM | 5.5 | 0.2% | Jun 17, 2025 | A flaw was found in the X server's request handling. Non-zero 'bytes to ignore' in a client's request can cause the serv... |
| CVE-2025-49177 | MEDIUM | 6.1 | 0.4% | Jun 17, 2025 | A flaw was found in the XFIXES extension. The XFixesSetClientDisconnectMode handler does not validate the request length... |
| CVE-2025-49176 | HIGH | 7.3 | 0.3% | Jun 17, 2025 | A flaw was found in the Big Requests extension. The request length is multiplied by 4 before checking against the maximu... |
| CVE-2025-49175 | MEDIUM | 6.1 | 0.3% | Jun 17, 2025 | A flaw was found in the X Rendering extension's handling of animated cursors. If a client provides no cursors, the serve... |
| CVE-2025-49071 | CRITICAL | 10 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in NasaTheme Flozen flozen-theme allows Upload a Web Shell... |
| CVE-2025-48333 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPQuark eForm - Wo... |
| CVE-2025-48274 | HIGH | 7.5 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpjobportal WP Job... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now