2025 CVE Vulnerabilities
45,279 CVEs published in 2025.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-47539 | CRITICAL | 9.8 | 30.9% | May 23, 2025 | Incorrect Privilege Assignment vulnerability in Arraytics Eventin wp-event-solution allows Privilege Escalation.This iss... |
| CVE-2025-47535 | HIGH | 8.6 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpopal Opal Woo Custom P... |
| CVE-2025-47532 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in CoinPayments CoinPayments.net Payment Gateway for WooCommerce coinpay... |
| CVE-2025-47530 | CRITICAL | 9.8 | 0.4% | May 23, 2025 | Deserialization of Untrusted Data vulnerability in WPFunnels WPFunnels wpfunnels allows Object Injection.This issue affe... |
| CVE-2025-47529 | MEDIUM | 6.5 | 0.3% | May 23, 2025 | Missing Authorization vulnerability in UX Design Experts Experto CTA Widget – Call To Action, Sticky CTA, Floating Butto... |
| CVE-2025-47513 | MEDIUM | 4.9 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in James Laforge Infocob CR... |
| CVE-2025-47512 | HIGH | 8.6 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in tainacan Tainacan tainac... |
| CVE-2025-47492 | HIGH | 8.6 | 1.2% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Dro... |
| CVE-2025-47478 | HIGH | 8.5 | 0.3% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileG... |
| CVE-2025-47461 | HIGH | 8.8 | 0.4% | May 23, 2025 | Authentication Bypass Using an Alternate Path or Channel vulnerability in mediaticus Subaccounts for WooCommerce subacco... |
| CVE-2025-47458 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in B2itech B2i Invest... |
| CVE-2025-47453 | CRITICAL | 9.8 | 0.5% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-47438 | CRITICAL | 9.8 | 0.6% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2025-46539 | CRITICAL | 9.3 | 0.4% | May 23, 2025 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFable Fable Extr... |
| CVE-2025-46537 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ctltwp Section Wid... |
| CVE-2025-46527 | MEDIUM | 6.5 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in LikeCoin Web3Press likec... |
| CVE-2025-46526 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in janekniefeldt My C... |
| CVE-2025-46518 | MEDIUM | 6.5 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in phpaddicted IGIT R... |
| CVE-2025-46515 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in M A Vinoth Kumar C... |
| CVE-2025-46493 | MEDIUM | 6.5 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordwebsoftware Cr... |
| CVE-2025-46490 | CRITICAL | 9.9 | 0.4% | May 23, 2025 | Unrestricted Upload of File with Dangerous Type vulnerability in wordwebsoftware Crossword Compiler Puzzles crossword-co... |
| CVE-2025-46488 | HIGH | 7.1 | 0.2% | May 23, 2025 | Missing Authorization vulnerability in dastan800 Visual Builder visual-builder allows Reflected XSS.This issue affects V... |
| CVE-2025-46487 | HIGH | 7.1 | 0.2% | May 23, 2025 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in sftranna EC Author... |
| CVE-2025-46486 | MEDIUM | 4.9 | 0.4% | May 23, 2025 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay ... |
| CVE-2025-46474 | HIGH | 8.1 | 0.6% | May 23, 2025 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
Check if your code is affected by 2025 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now