2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47680 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michel - xiligroup... |
| CVE-2025-47678 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FunnelCockpit Funn... |
| CVE-2025-47673 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tychesoftwares Arc... |
| CVE-2025-47672 | HIGH | 8.1 | 0.4% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47671 | HIGH | 7.6 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LETSCMS MLM Softwa... |
| CVE-2025-47670 | HIGH | 8.1 | 0.4% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47663 | CRITICAL | 9.9 | 0.3% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in mojoomla Hospital Management System allows Upload a Web... |
| CVE-2025-47660 | HIGH | 8.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in Codexpert, Inc WC Affiliate wc-affiliate allows Object Injection.This... |
| CVE-2025-47658 | HIGH | 8.8 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in ELEXtensions ELEX WordPress HelpDesk & Customer Ticketi... |
| CVE-2025-47646 | CRITICAL | 9.8 | 21.7% | May 23, 2025 | Weak Password Recovery Mechanism for Forgotten Password vulnerability in Gilblas Ngunte Possi PSW Front-end Login & Regi... |
| CVE-2025-47642 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in Ajar Productions Ajar in5 Embed ajar-productions-in5-em... |
| CVE-2025-47641 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in printcart Printcart Web to Print Product Designer for W... |
| CVE-2025-47640 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in printcart Printcar... |
| CVE-2025-47637 | CRITICAL | 10 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in STAGGS STAGGS staggs allows Upload a Web Shell to a Web... |
| CVE-2025-47631 | HIGH | 8.8 | 0.3% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in mojoomla Hospital Management System allows Privilege Escalation. This is... |
| CVE-2025-47619 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in 6Storage 6Storage Rentals 6storage-rentals allows Path Traversal.This issue affec... |
| CVE-2025-47618 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mortgage Calculato... |
| CVE-2025-47613 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mojoomla School Ma... |
| CVE-2025-47611 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Khaled User Meta u... |
| CVE-2025-47603 | HIGH | 7.5 | 0.5% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Belingo belingoGeo belin... |
| CVE-2025-47599 | CRITICAL | 9.3 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in facturante Factura... |
| CVE-2025-47575 | HIGH | 8.5 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mojoomla School Ma... |
| CVE-2025-47568 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in ZoomIt ZoomSounds dzs-zoomsounds allows Object Injection.This issue a... |
| CVE-2025-47558 | HIGH | 7.5 | 0.4% | May 23, 2025 | Missing Authorization vulnerability in RomanCode MapSVG mapsvg allows Accessing Functionality Not Properly Constrained b... |
| CVE-2025-47541 | HIGH | 7.5 | 0.4% | May 23, 2025 | Insertion of Sensitive Information Into Sent Data vulnerability in WPFunnels Mail Mint mail-mint allows Retrieve Embedde... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now