2025 CVE Vulnerabilities
45,269 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-49269 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in Anton Vanyukov Market Exporter market-exporter allows Cross Site Requ... |
| CVE-2025-49268 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in Soft8Soft LLC Verge3D verge3d allows Exploiting Incorrectly Configured Access Con... |
| CVE-2025-49263 | HIGH | 7.6 | 0.4% | Jun 6, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WCVendors WC Vendo... |
| CVE-2025-49262 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in shaonsina Sina Ext... |
| CVE-2025-49250 | MEDIUM | 4.3 | 0.3% | Jun 6, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in cmoreira Team Showcase team-showcase-cm allow... |
| CVE-2025-49248 | MEDIUM | 4.3 | 0.2% | Jun 6, 2025 | Missing Authorization vulnerability in cmoreira Team Showcase team-showcase-cm allows Exploiting Incorrectly Configured ... |
| CVE-2025-49246 | MEDIUM | 4.3 | 0.2% | Jun 6, 2025 | Missing Authorization vulnerability in cmoreira Testimonials Showcase testimonials-showcase allows Exploiting Incorrectl... |
| CVE-2025-49244 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vova Shortcodes Ul... |
| CVE-2025-49243 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark ShiftNa... |
| CVE-2025-49242 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sevenspark Bellows... |
| CVE-2025-49241 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in bobbingwide oik oik allows Exploiting Incorrectly Configured Access Control Secur... |
| CVE-2025-49240 | MEDIUM | 4.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in nK DocsPress docspress allows Exploiting Incorrectly Configured Access Control Se... |
| CVE-2025-49239 | MEDIUM | 5.4 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in tychesoftwares Print Invoice & Delivery Notes for WooCommerce woocomm... |
| CVE-2025-49238 | MEDIUM | 4.3 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in everestthemes Everest Backup everest-backup allows Cross Site Request... |
| CVE-2025-49237 | HIGH | 7.4 | 0.2% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in POEditor POEditor poeditor allows Path Traversal.This issue affects P... |
| CVE-2025-49236 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in raychat Raychat raychat allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-49235 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rometheme RTMKit r... |
| CVE-2025-49073 | CRITICAL | 9.8 | 0.4% | Jun 6, 2025 | Deserialization of Untrusted Data vulnerability in axiomthemes Sweet Dessert sweet-dessert allows Object Injection.This ... |
| CVE-2025-49072 | CRITICAL | 9.8 | 0.4% | Jun 6, 2025 | Deserialization of Untrusted Data vulnerability in AncoraThemes Mr. Murphy mr-murphy allows Object Injection.This issue ... |
| CVE-2025-38000 | HIGH | 7.8 | 0.2% | Jun 6, 2025 | In the Linux kernel, the following vulnerability has been resolved: sch_hfsc: Fix qlen accounting bug when using peek i... |
| CVE-2025-31025 | MEDIUM | 6.5 | 0.2% | Jun 6, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Blocksera Image Ho... |
| CVE-2025-31000 | MEDIUM | 5.3 | 0.3% | Jun 6, 2025 | Missing Authorization vulnerability in Miguel Fuentes Payment QR WooCommerce payment-qr-woo allows Exploiting Incorrectl... |
| CVE-2025-30999 | HIGH | 7.5 | 0.5% | Jun 6, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-30997 | MEDIUM | 5.4 | 0.2% | Jun 6, 2025 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Car Repair Services car-repair-services allows Server ... |
| CVE-2025-30995 | HIGH | 7.1 | 0.1% | Jun 6, 2025 | Cross-Site Request Forgery (CSRF) vulnerability in OTWthemes Widgetize Pages Light widgetize-pages-light allows Stored X... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now