2025 CVE Vulnerabilities
45,267 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-48145 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michal Jaworski Tr... |
| CVE-2025-48118 | HIGH | 8.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WpExperts Hub Wooc... |
| CVE-2025-48111 | MEDIUM | 4.3 | 0.1% | Jun 17, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in YITHEMES YITH PayPal Express Checkout for WooCommerce allows Cross Si... |
| CVE-2025-47573 | CRITICAL | 9.3 | 0.4% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Ma... |
| CVE-2025-47572 | HIGH | 7.5 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47559 | CRITICAL | 9.9 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RomanCode MapSVG mapsvg allows Upload a Web Shell to a ... |
| CVE-2025-47452 | CRITICAL | 9.9 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in RexTheme WP VR wpvr allows Upload a Web Shell to a Web ... |
| CVE-2025-39508 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NasaTheme Nasa Cor... |
| CVE-2025-39486 | HIGH | 8.5 | 0.2% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Rankie ... |
| CVE-2025-39479 | CRITICAL | 9.3 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in smartiolabs Smart ... |
| CVE-2025-34508 | MEDIUM | 6.3 | 62.1% | Jun 17, 2025 | A path traversal vulnerability exists in the file dropoff functionality of ZendTo versions 6.15-7 and prior. This could... |
| CVE-2025-32549 | HIGH | 7.5 | 0.4% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-32510 | CRITICAL | 10 | 0.4% | Jun 17, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ovatheme Ovatheme Events Manager ova-events-manager all... |
| CVE-2025-31919 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in themeton Spare allows Object Injection. This issue affects Spare: fro... |
| CVE-2025-30988 | HIGH | 7.1 | 0.2% | Jun 17, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in _CreativeMedia_ El... |
| CVE-2025-30618 | CRITICAL | 9.8 | 0.5% | Jun 17, 2025 | Deserialization of Untrusted Data vulnerability in yuliaz Rapyd Payment Extension for WooCommerce rapyd-payments allows ... |
| CVE-2025-30562 | HIGH | 8.5 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpdistillery Navig... |
| CVE-2025-29002 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-28991 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-28972 | HIGH | 7.6 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Suhas Surse WP Emp... |
| CVE-2025-24773 | CRITICAL | 9.3 | 0.3% | Jun 17, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla WPCRM - C... |
| CVE-2025-24761 | HIGH | 8.1 | 0.5% | Jun 17, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-6069 | MEDIUM | 4.3 | 0.5% | Jun 17, 2025 | The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs po... |
| CVE-2025-4879 | HIGH | 7.8 | 0.1% | Jun 17, 2025 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows |
| CVE-2025-4404 | CRITICAL | 9.1 | 1.8% | Jun 17, 2025 | A privilege escalation from host to domain vulnerability was found in the FreeIPA project. The FreeIPA package fails to ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now