2025 CVE Vulnerabilities
45,268 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49281 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49280 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49279 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49278 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49277 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49276 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49275 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-49265 | HIGH | 7.5 | 0.3% | Jun 9, 2025 | Missing Authorization vulnerability in WP Swings Membership For WooCommerce membership-for-woocommerce allows Accessing ... |
| CVE-2025-48281 | CRITICAL | 9.3 | 1.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mystyleplatform My... |
| CVE-2025-48279 | HIGH | 7.1 | 0.2% | Jun 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Richard Perdaan WC... |
| CVE-2025-48267 | CRITICAL | 9.1 | 0.4% | Jun 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ThimPress WP Pipes allow... |
| CVE-2025-48261 | HIGH | 7.5 | 0.3% | Jun 9, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in MultiVendorX MultiVendorX dc-woocommerce-multi-vendor... |
| CVE-2025-48147 | MEDIUM | 6.5 | 0.2% | Jun 9, 2025 | Missing Authorization vulnerability in Crypto Cloud CryptoCloud - Crypto Payment Gateway cryptocloud-crypto-payment-gate... |
| CVE-2025-48143 | HIGH | 7.1 | 0.2% | Jun 9, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in salesup2019 Formul... |
| CVE-2025-48141 | CRITICAL | 9.3 | 0.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alex Zaytseff Mult... |
| CVE-2025-48140 | CRITICAL | 9.9 | 0.3% | Jun 9, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi all... |
| CVE-2025-48139 | MEDIUM | 6.5 | 0.2% | Jun 9, 2025 | Missing Authorization vulnerability in relentlo StyleAI relentlosoftware allows Accessing Functionality Not Properly Con... |
| CVE-2025-48130 | HIGH | 7.5 | 0.4% | Jun 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spicethemes Spice Blocks... |
| CVE-2025-48129 | CRITICAL | 9.8 | 0.5% | Jun 9, 2025 | Incorrect Privilege Assignment vulnerability in Holest Engineering Spreadsheet Price Changer for WooCommerce and WP E-co... |
| CVE-2025-48126 | CRITICAL | 9.8 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48125 | HIGH | 8.1 | 0.4% | Jun 9, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-48124 | HIGH | 7.5 | 0.5% | Jun 9, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Holest Engineering Sprea... |
| CVE-2025-48123 | CRITICAL | 10 | 0.4% | Jun 9, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in Holest Engineering Spreadsheet Price Changer ... |
| CVE-2025-48122 | CRITICAL | 9.3 | 0.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Holest Engineering... |
| CVE-2025-47651 | HIGH | 8.5 | 0.3% | Jun 9, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Infility Infility ... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now